CVE-2026-62208: OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.5 - Compensating control
Ensure the affected SSE redirect/Authorization header forwarding path is not reachable by lower-trust callers (restrict network/API access so lower-trust input cannot reach the affected path).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62208?
CVE-2026-62208 has a medium severity rating of 6.
How do I fix CVE-2026-62208?
To fix CVE-2026-62208, upgrade OpenClaw to version 2026.6.5 or later.
What impact does CVE-2026-62208 have on my system?
CVE-2026-62208 can allow lower-trust callers to execute actions beyond their intended authorization due to Authorization header forwarding.
Is CVE-2026-62208 exploitable remotely?
Yes, CVE-2026-62208 is exploitable remotely if the affected feature is enabled and accessible.
Which versions of OpenClaw are affected by CVE-2026-62208?
OpenClaw versions before 2026.6.5 are affected by CVE-2026-62208.