CVE-2026-62209: OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.5 - Configuration
Disable the ClickClack agent-mode dispatch feature until all affected OpenClaw versions (2026.5.10-beta.1 before 2026.6.5) are upgraded to 2026.6.5, since it can bypass the toolsAllow policy check when reachable.
OpenClaw ClickClack agent-mode dispatch feature enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62209?
The severity of CVE-2026-62209 is high, with a score of 7.6.
How do I fix CVE-2026-62209?
To fix CVE-2026-62209, upgrade OpenClaw to version 2026.6.5 or later.
What does CVE-2026-62209 exploit?
CVE-2026-62209 exploits an authorization bypass in the agent-mode dispatch feature of OpenClaw.
Who is affected by CVE-2026-62209?
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 are affected by CVE-2026-62209.
What could happen if CVE-2026-62209 is exploited?
If exploited, CVE-2026-62209 could allow a lower-trust caller to perform unauthorized actions.