CVE-2026-62223: OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized actions when the affected feature is enabled and reachable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62223?
The severity of CVE-2026-62223 is classified as high, with a rating of 7.7.
How do I fix CVE-2026-62223?
To fix CVE-2026-62223, upgrade OpenClaw to version 2026.5.18 or later.
What type of vulnerability is associated with CVE-2026-62223?
CVE-2026-62223 is classified as an authorization bypass vulnerability.
Who is affected by CVE-2026-62223?
Users of OpenClaw versions prior to 2026.5.18 are affected by CVE-2026-62223.
What can attackers do with CVE-2026-62223?
Attackers can exploit CVE-2026-62223 to perform unauthorized actions due to the authorization bypass in the device-pair approval feature.