Description
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
Published: 2026-07-17
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions prior to 2026.5.19 contain an authorization bypass flaw in the browser act route that does not correctly honor current‑tab URL checks. An attacker who can access the application with a lower‑trust credential or can craft a request to a configured input path can trigger actions that normally require greater authorization or policy verification, potentially allowing unauthorized data access or command execution.

Affected Systems

The vulnerability affects the OpenClaw application. All installations using OpenClaw version 2026.3.28 or earlier are susceptible. Versions 2026.5.19 and later include the fixed authorization check.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity and the EPSS score of less than 1 % shows that exploitation is not currently widespread. The flaw is not listed in the CISA KEV catalog. Attackers would likely use a browser‑based request to the vulnerable route, requiring network access to the application and either a lower‑trust login or the ability to manipulate input paths. Successful exploitation would allow privileged operations without meeting normal authorization checks.

Generated by OpenCVE AI on July 31, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw 2026.5.19 or later, which incorporates the fix for the authorization check in the browser act route.
  • Restrict or remove lower‑trust user accounts from accessing the browser act route until the update can be applied, ensuring only privileged users can use that path.
  • Enable comprehensive logging for accesses to the browser act route, review logs regularly for anomalous activity by non‑privileged users, and investigate any suspicious behavior.

Generated by OpenCVE AI on July 31, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
Title OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-918
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-17T10:53:19.719Z

Reserved: 2026-07-13T16:40:10.961Z

Link: CVE-2026-62226

cve-icon Vulnrichment

Updated: 2026-07-17T10:53:15.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)