SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-62220

MEDIUM · CVSS 5.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

OpenClaw versions prior to 2026.5.26 are vulnerable to a bypass of non-browser rate limits on WebSocket authentication attempts, which can be exploited by lower-trust callers. This vulnerability can lead to resource exhaustion on the gateway, potentially impacting service availability. Organizations using affected versions should prioritize remediation to mitigate the risk of denial-of-service conditions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62220
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)