CVE-2026-62190: OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62190?
The severity of CVE-2026-62190 is rated high with a score of 8.8.
What does CVE-2026-62190 affect?
CVE-2026-62190 affects OpenClaw versions prior to 2026.6.9.
How do I fix CVE-2026-62190?
To fix CVE-2026-62190, upgrade OpenClaw to version 2026.6.9 or later.
What are the potential impacts of CVE-2026-62190?
CVE-2026-62190 allows attackers to bypass authorization mechanisms, potentially leading to unauthorized actions.
Who is affected by CVE-2026-62190?
Users and administrators of OpenClaw systems running versions before 2026.6.9 are impacted by CVE-2026-62190.