Openclaw · Openclaw · CVE-2026-62208
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.6.5
**Description**
OpenClaw may forward Authorization headers during Model Context Protocol (MCP) Server-Sent Events (SSE) redirects. If the affected feature is enabled and accessible, a lower-trust caller or a configured input path could perform or persist actions that exceed the caller's intended authorization level. The overall impact is determined by the operator's configuration and the ability of lower-trust input to reach the affected path.
**Recommendations**
Update OpenClaw to version 2026.6.5 or later.