---
id: CVE-2026-62229
title: >-
  OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in
  exec allowlist glob matching that allows lower-trust callers to execute
  actions beyond intended authorization
summary: >-
  OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in
  exec allowlist glob matching that allows lower-trust callers to execute
  actions beyond intended authorization. Attackers can craft input paths that
  traverse the a…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
published: '2026-07-17'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62229'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-34mr-7r3m-gfg7
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-glob-matching
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00716
epssPercentile: 0.51792
ingestedAt: '2026-07-18T21:25:07.843Z'
---

## Overview

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
