Openclaw · Openclaw · CVE-2026-62217
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions 2026.5.14-beta.1 through 2026.5.26
**Description**
An authorization flaw exists in the QQBot exec approvals feature. When this feature is enabled and reachable, a lower-trust caller or a configured input path can execute or persist actions that exceed the caller's intended authorization. This allows senders who are not on the allowlist to perform unauthorized operations.
**Recommendations**
Update OpenClaw to version 2026.5.27.
As a temporary mitigation, disable the QQBot exec approvals feature.