CVE-2026-62196
EUVD-2026-4353613.07.2026, 22:16
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 2026.3.22 ≤ 𝑥 < 2026.6.6 |
𝑥
= Vulnerable software versions