CVE-2026-62217: OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.27 - Configuration
Disable the QQBot exec approvals feature in OpenClaw to prevent the authentication/authorization bypass when it is enabled and reachable.
OpenClaw QQBot exec approvals feature enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62217?
CVE-2026-62217 has a high severity rating of 7.7.
How do I fix CVE-2026-62217?
To fix CVE-2026-62217, upgrade OpenClaw to version 2026.5.27 or later.
What is the risk associated with CVE-2026-62217?
CVE-2026-62217 has a risk score of 79, indicating significant potential impact.
What type of vulnerability is CVE-2026-62217?
CVE-2026-62217 is an authorization flaw that allows an authentication bypass.
Which feature in OpenClaw is affected by CVE-2026-62217?
The vulnerability in CVE-2026-62217 affects the QQBot exec approvals feature.