CVE-2026-62195
OpenClaw OpenClaw, openclaw
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.
- CVSS
- 8.7
- EPSS
- 0.23% 13.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14