Beveiligingsadvies

CVE-2026-62216

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-17 00:06:57
Laatst bijgewerkt 2026-07-23 19:26:02
Toegewezen door VulnCheck
CVSS-score 5.0
Status PUBLISHED

Beschrijving

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.