CVE-2026-62193: OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62193?
CVE-2026-62193 has a medium severity rating of 4.9.
How do I fix CVE-2026-62193?
To fix CVE-2026-62193, upgrade OpenClaw to version 2026.6.9 or later.
What systems are affected by CVE-2026-62193?
CVE-2026-62193 affects OpenClaw versions 2026.6.5 and earlier.
What does the vulnerability CVE-2026-62193 allow an attacker to do?
CVE-2026-62193 allows an attacker to bypass authentication checks during plugin installation.
Is CVE-2026-62193 exploitable remotely?
Yes, CVE-2026-62193 is exploitable remotely due to the nature of the plugin installation process.