CVE-2026-62226EPSS p24.6%
CVE-2026-62226CVE-2026-62226
openclaw / openclaw
Description
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
Scoring
| CVSS | 8.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
| EPSS | 0.33% probability of exploitation · percentile 24.6% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-21 |