CVE-2026-62207: OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62207?
CVE-2026-62207 has a severity rating of high, with a score of 7.7.
How do I fix CVE-2026-62207?
To fix CVE-2026-62207, upgrade OpenClaw to version 2026.6.5 or later.
What type of vulnerability is CVE-2026-62207?
CVE-2026-62207 is an authentication bypass vulnerability that allows unauthorized access to admin tools.
Who is affected by CVE-2026-62207?
OpenClaw users running versions prior to 2026.6.5 are affected by CVE-2026-62207.
What can attackers do with CVE-2026-62207?
Attackers can exploit CVE-2026-62207 to perform actions requiring higher-level authorization by bypassing authentication checks.