Known Vulnerabilities for products from Openclaw
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Openclaw".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66421 json | Not Provided | 2026-07-30 | 2026-07-31 | |
| CVE-2026-66418 json | Not Provided | 2026-07-30 | 2026-07-31 | |
| CVE-2026-62229 json | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-tru... | Not Provided | 2026-07-17 | 2026-07-30 |
| CVE-2026-62228 json | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers... | Not Provided | 2026-07-17 | 2026-07-29 |
| CVE-2026-62227 json | OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail ... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62226 json | OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to prop... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62225 json | Not Provided | 2026-07-17 | 2026-07-21 | |
| CVE-2026-62224 json | Not Provided | 2026-07-17 | 2026-07-17 | |
| CVE-2026-62223 json | Not Provided | 2026-07-17 | 2026-07-18 | |
| CVE-2026-62222 json | OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins.... | Not Provided | 2026-07-17 | 2026-07-29 |
| CVE-2026-62221 json | OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. Whe... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62220 json | OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on ... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62219 json | OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A ... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62218 json | OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that all... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62217 json | OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the featur... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62216 json | OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or config... | Not Provided | 2026-07-17 | 2026-07-23 |
| CVE-2026-62215 json | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-t... | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-62214 json | OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust ... | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-62213 json | OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trus... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-62212 json | OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature ... | Not Provided | 2026-07-17 | 2026-07-20 |