CVE-2026-62196
OpenClaw OpenClaw, openclaw
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.
- CVSS
- 8.7
- EPSS
- 0.23% 13.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14