CVE-2026-62196: OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.6
Event History
Frequently Asked Questions
What is the risk and severity of CVE-2026-62196?
CVE-2026-62196 has a risk score of 69 and a severity rating of high at 8.3.
What type of vulnerability is CVE-2026-62196?
CVE-2026-62196 is an authorization bypass vulnerability affecting OpenClaw.
How can CVE-2026-62196 be exploited?
CVE-2026-62196 can be exploited by attackers using lower-trust access to perform actions requiring stronger authorization through WhatsApp group ID validation.
What versions of OpenClaw are affected by CVE-2026-62196?
OpenClaw versions 2026.3.22 and earlier are affected by CVE-2026-62196.
How do I fix CVE-2026-62196?
To mitigate CVE-2026-62196, upgrade OpenClaw to version 2026.6.6 or later.