CVE-2026-62226: OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62226?
CVE-2026-62226 has a medium severity rating of 5.1.
What type of vulnerability is identified in CVE-2026-62226?
CVE-2026-62226 is an authorization bypass vulnerability.
How do I fix CVE-2026-62226?
To fix CVE-2026-62226, upgrade OpenClaw to version 2026.5.19 or later.
Who is affected by CVE-2026-62226?
Users of OpenClaw versions 2026.3.28 to 2026.5.18 are affected by CVE-2026-62226.
What can attackers do with CVE-2026-62226?
Attackers with lower-trust access can perform actions that require stronger authorization due to the bypass in the browser act route.