High severity7.1NVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
CVE-2026-62219
CVE-2026-62219
Description
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-724r-v4wf-mqc5nvdVendor Advisory
- www.vulncheck.com/advisories/openclaw-authorization-bypass-via-blank-agent-idsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.