SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62188

HIGH · CVSS 8.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Versions 2026.6.6 and earlier of OpenClaw @openclaw/feishu are vulnerable due to an incorrect authorization flaw that allows lower-trust users to bypass account-specific disablement settings, potentially leading to unauthorized actions. This vulnerability poses a significant risk to organizations relying on these versions for secure permission management. Users of the affected software should prioritize upgrading to version 2026.6.9 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62188
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)