CVE-2026-62221: OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.26 - Configuration
Disable the ClickClack allowFrom feature or ensure it is not enabled and not reachable (only trusted callers/paths) to prevent authorization bypass via allowFrom.
OpenClaw (ClickClack) allowFrom feature authorization (allowFrom) = disable or ensure it is not enabled/reachable
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62221?
The severity of CVE-2026-62221 is classified as low, with a score of 2.3.
How do I fix CVE-2026-62221?
To fix CVE-2026-62221, upgrade OpenClaw to version 2026.5.26 or later.
What does CVE-2026-62221 affect?
CVE-2026-62221 affects OpenClaw versions before 2026.5.26, specifically relating to an authorization bypass in the allowFrom feature.
What kind of vulnerability is CVE-2026-62221?
CVE-2026-62221 is an authorization bypass vulnerability allowing unauthorized actions under certain conditions.
Is CVE-2026-62221 easy to exploit?
While the risk level is low, CVE-2026-62221 could potentially be exploited if the affected feature is reachable by a lower-trust caller.