Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs
CVE-2026-62219
Description
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-724r-v4wf-mqc5mitrevendor-advisory
- www.vulncheck.com/advisories/openclaw-authorization-bypass-via-blank-agent-idsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.