CVE-2026-62194: OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62194?
The severity of CVE-2026-62194 is high, with a score of 8.8.
How does CVE-2026-62194 exploit privilege escalation?
CVE-2026-62194 allows lower-trust users to execute actions beyond their authorization through misconfigured plugin install commands.
Which versions of OpenClaw are affected by CVE-2026-62194?
OpenClaw versions 2026.5.20 and earlier are affected by CVE-2026-62194.
How can I fix CVE-2026-62194?
To fix CVE-2026-62194, upgrade OpenClaw to version 2026.6.9 or later.
What are potential risks associated with CVE-2026-62194?
The risks of CVE-2026-62194 include unauthorized actions being executed by attackers, leading to potential data breaches or system compromise.