Aller au contenu

Fiche vulnérabilité

CVE-2026-62198 : faille moyenne openclaw openclaw (CVSS 5.4)

Description

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
13 juil. 2026
Dernière mise à jour
14 juil. 2026

Produits concernés

  • openclaw openclaw

Références

Rechercher une autre vulnérabilité dans la base CVE