CVE-2026-62189: OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62189?
CVE-2026-62189 has a severity rating of high, specifically 7.1.
How do I fix CVE-2026-62189?
To fix CVE-2026-62189, upgrade OpenClaw to version 2026.6.9 or later.
What is the impact of CVE-2026-62189?
CVE-2026-62189 allows attackers to bypass policy checks and authorization boundaries through symlink following.
Which versions of OpenClaw are affected by CVE-2026-62189?
OpenClaw versions prior to 2026.6.9 are affected by CVE-2026-62189.
Is CVE-2026-62189 a remote or local vulnerability?
CVE-2026-62189 is a remote vulnerability that can be exploited by attackers through symlink parents.