CVE-2026-62217
EUVD-2026-4510517.07.2026, 02:18
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 2026.5.14 ≤ 𝑥 < 2026.5.27 |
𝑥
= Vulnerable software versions