CVE-2026-62193 Details
Description
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.
A vulnerability allowing authentication bypass has been identified in OpenClaw versions 2026.6.5 prior to 2026.6.9. This issue arises in the plugin install wrappers, where the install policy authorization check could be skipped. When the affected feature is enabled and accessible, a lower-trust caller or a configured input path might execute or persist actions beyond the caller's intended authorization. The impact of this vulnerability varies based on the operator's configuration and the ability of lower-trust input to reach the affected path.
Users are advised to upgrade to OpenClaw version 2026.6.9 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it if not needed. As a general hardening measure, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-wgq8-x5wm-g4rw | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-plugin-install | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | >= 2026.6.5, < 2026.6.9 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | New CVE Received | [email protected] |