Skip to content
Threat Feed
high threat exploited

CVE-2026-62202 - OpenClaw Privilege Escalation via Isolated Cron Jobs

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability, CVE-2026-62202, in isolated cron jobs that allows lower-trust callers to regain denied execution tools and execute or persist actions beyond their intended authorization by leveraging misconfigured input paths.

CVE search metadata

CVE search record: CVE-2026-62202. Severity: high. CVSS: 8.8. KEV: no. Product: OpenClaw (< 2026.6.9). Brief: CVE-2026-62202 - OpenClaw Privilege Escalation via Isolated Cron Jobs. Brief link: https://feed.craftedsignal.io/briefs/2026-07-openclaw-privilege-escalation/

CVE search record: CVE-2026-62206. Severity: high. CVSS: 7.1. KEV: no. Product: OpenClaw (< 2026.6.9). Brief: CVE-2026-62202 - OpenClaw Privilege Escalation via Isolated Cron Jobs. Brief link: https://feed.craftedsignal.io/briefs/2026-07-openclaw-privilege-escalation/

What's new

  • 1. added CVE-2026-62206 Jul 17, 02:24 via nvd

OpenClaw versions 2026.6.1 through 2026.6.8 are affected by a high-severity privilege escalation vulnerability, tracked as CVE-2026-62202, located within the isolated cron job feature. This flaw permits users or processes with lower trust to bypass intended authorization and re-enable execution tools that were previously denied to them. Attackers can leverage misconfigured input paths within this cron functionality to execute commands or establish persistence on the system with elevated privileges. The vulnerability has a CVSS v3.1 base score of 8.8, indicating a critical risk if exploited. There is currently no public information suggesting active exploitation of this vulnerability in the wild; however, its nature allows for significant impact upon successful exploitation.

Attack Chain

  1. An attacker identifies an OpenClaw instance running an affected version (2026.6.1 through 2026.6.8).
  2. The attacker obtains initial access to the system where OpenClaw is installed, operating with lower-trust privileges.
  3. The attacker then identifies specific isolated cron jobs with misconfigured input paths within the OpenClaw environment.
  4. By providing specially crafted input to these identified misconfigured paths, the attacker circumvents the normal authorization checks.
  5. This bypass allows the attacker to regain access to or modify execution tools and capabilities that were intended to be restricted for their current trust level.
  6. The vulnerable cron job then executes the attacker's manipulated actions or commands with elevated privileges, achieving unauthorized code execution or establishing persistence.

Impact

Successful exploitation of CVE-2026-62202 results in privilege escalation, allowing a lower-trust attacker to gain higher access levels on the compromised system. This enables attackers to execute arbitrary code, modify system configurations, install malicious software, or establish persistent access beyond their initial authorization. While specific victim numbers or targeted sectors are not available, any organization utilizing vulnerable OpenClaw installations is at risk. The direct consequence for a compromised system is a loss of integrity and confidentiality, with potential for full system control.

Recommendation

  • Immediately upgrade all OpenClaw installations to version 2026.6.9 or later to patch CVE-2026-62202.
  • Review cron job configurations within OpenClaw to ensure input paths are correctly secured and adhere to the principle of least privilege, as specified in the vendor's updated documentation.

Indicators of compromise

2

url

TypeValue
urlhttps://github.com/openclaw/openclaw/security/advisories/GHSA-f6p7-6326-vf7v
urlhttps://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-moderation-actions