VYPR
High severity8.5NVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026

CVE-2026-62226

CVE-2026-62226

Description

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.

Affected products

2
  • OpenClaw/Openclaw2 versions
    cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: >=2026.3.28,<2026.5.19
    • (no CPE)range: <2026.5.19

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.