
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62229 is an authorization bypass vulnerability in OpenClaw's exec allowlist glob matching feature that allows lower-trust authenticated callers to execute actions beyond their intended authorization. Affected versions are all OpenClaw (npm package) releases before 2026.5.18. The vulnerability was published on July 17, 2026, with the security advisory originally published by maintainer joshavant on June 30, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Github Advisory).
The root cause is improper glob pattern matching in OpenClaw's exec allowlist feature, classified as CWE-22 (Path Traversal) and CWE-863 (Incorrect Authorization). An attacker with low-privilege network access can craft input paths that traverse or bypass the allowlist glob patterns, causing the authorization check to incorrectly permit execution of restricted actions. Exploitation requires the exec allowlist feature to be enabled and reachable by lower-trust callers; it does not affect trusted Gateway operators, installed plugins, or intentional local execution surfaces unless a separate authorization boundary is crossed. No public proof-of-concept code has been identified (GitHub Advisory, Github Advisory).
Successful exploitation allows an authenticated lower-trust user to execute or persist actions that should be restricted by the exec allowlist, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. Practical impact is configuration-dependent: environments where the exec allowlist feature is enabled and accessible to lower-trust users face the greatest risk of unauthorized command execution and persistent unauthorized modifications. The vulnerability does not affect subsequent/downstream systems directly, but unauthorized execution within the OpenClaw context could facilitate further lateral movement depending on the operator's deployment (GitHub Advisory, Github Advisory).
../, URL-encoded variants, or alternate slash encodings) to craft a path that matches an allowlisted glob pattern while resolving to a restricted execution target.../, %2e%2e%2f, or encoded slash variants).The first stable patched version is OpenClaw 2026.5.18 (npm); operators should upgrade immediately. If immediate patching is not possible, restrict the exec allowlist feature to trusted operators only or disable it entirely when not needed. As additional hardening, keep channel and tool allowlists narrow, avoid sharing a single Gateway between mutually untrusted users, and review execution logs for signs of unauthorized access. Credits for discovery go to reporter zsxsoft and sponsor KeenSecurityLab (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."