
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62226 is an authorization bypass vulnerability in OpenClaw's browser act route that fails to properly validate current-tab URL checks, classified as Server-Side Request Forgery (CWE-918) and Improper Access Control (CWE-284). It affects OpenClaw versions 2026.3.28 through 2026.5.19 (exclusive) for the Node.js ecosystem. The vulnerability was published on July 17, 2026, with a patch available in version 2026.5.19. It carries a CVSS v3.1 base score of 8.5 (High) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Github Advisory).
The root cause is insufficient validation of current-tab URL checks within OpenClaw's browser act route, classified under CWE-918 (SSRF) and CWE-284 (Improper Access Control). An attacker with lower-trust access or control over configured input paths can send crafted requests to the browser act route, bypassing authorization and policy checks that should gate higher-privilege actions. The vulnerability requires the affected feature to be enabled and reachable, and exploitation depends on the operator's configuration and whether lower-trust input can reach the vulnerable path. The advisory notes this does not affect OpenClaw's trusted-operator model (authenticated Gateway operators, installed plugins, and intentional local execution surfaces remain trusted) unless a separate policy or auth boundary is crossed (GitHub Advisory).
Successful exploitation allows an authenticated user with lower-trust access to bypass authorization controls and perform actions that should require stronger authorization or policy checks, primarily impacting confidentiality of subsequent/downstream systems (rated High in CVSS v3.1). The scope change in CVSS v3.1 indicates that the impact extends beyond the vulnerable component itself, potentially exposing restricted functionality and sensitive data across system boundaries. Integrity impact is rated Low, and there is no availability impact. Practical impact is configuration-dependent and is most severe when lower-trust input paths can reach the browser act route (GitHub Advisory, Github Advisory).
Upgrade OpenClaw to version 2026.5.19 or later, which contains the fix for this vulnerability (GitHub Advisory). Prior to upgrading, restrict the browser act route to trusted operators only, or disable the feature entirely if not needed. As additional hardening, keep channel and tool allowlists narrow, avoid sharing a single Gateway between mutually untrusted users, and implement network-level access controls to limit who can reach the affected route.
The advisory was credited to reporter zsxsoft and sponsored by KeenSecurityLab, suggesting coordinated disclosure with security research involvement (GitHub Advisory). No significant broader media coverage or notable community commentary has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."