Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas
CVE-2026-62215
Description
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-vr7j-7684-7gm5mitrevendor-advisory
- www.vulncheck.com/advisories/openclaw-authentication-bypass-via-http-canvasmitrethird-party-advisory
News mentions
0No linked articles in our index yet.