8.3highHigh

CVE-2026-62196

Openclaw Openclaw

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
8.3 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS v4
8.7
Weakness
CWE-863
Assigned by
disclosure@vulncheck.com

Dates

Published
2026-07-13
Last modified
2026-09-05
Sources
NVD

Affected products

  • Openclaw Openclaw2026.3.22 - 2026.6.6

As listed in the NVD configuration data. Not a statement about your estate.

References