CVE-2026-62192: OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62192?
CVE-2026-62192 has a high severity rating of 8.1.
How do I fix CVE-2026-62192?
To fix CVE-2026-62192, update OpenClaw to version 2026.6.9 or later.
What are the potential impacts of CVE-2026-62192?
CVE-2026-62192 allows lower-trust callers to bypass authorization checks, potentially compromising sensitive actions.
In which versions of OpenClaw is CVE-2026-62192 present?
CVE-2026-62192 is present in OpenClaw versions 2026.6.6 before 2026.6.9.
What kind of vulnerability is CVE-2026-62192?
CVE-2026-62192 is an authorization bypass vulnerability affecting Discord guild actions.