High severity8.0NVD Advisory· Published Jul 17, 2026· Updated Jul 20, 2026
CVE-2026-62215
CVE-2026-62215
Description
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-vr7j-7684-7gm5nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-authentication-bypass-via-http-canvasnvdThird Party Advisory
News mentions
0No linked articles in our index yet.