Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 15, 2026
OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback
CVE-2026-62195
Description
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-52xj-c9p8-78cvmitrevendor-advisory
- www.vulncheck.com/advisories/openclaw-authorization-bypass-via-mcp-loopbackmitrethird-party-advisory
News mentions
0No linked articles in our index yet.