2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-62236MEDIUM5.4grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec...
CVE-2026-62235MEDIUM6.3Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al...
CVE-2026-62234HIGH8.4Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.w...
CVE-2026-62233HIGH8.8grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints...
CVE-2026-62232CRITICAL9.1Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS...
CVE-2026-62231HIGH8.6The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created wit...
CVE-2026-62230HIGH8.7Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access t...
CVE-2026-62229HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lowe...
CVE-2026-62228HIGH8.8OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca...
CVE-2026-62227HIGH7.7OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that ...
CVE-2026-62226HIGH8.5OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to...
CVE-2026-62225MEDIUM5.4OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows l...
CVE-2026-62224MEDIUM5.4OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu...
CVE-2026-62223HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows ...
CVE-2026-62222HIGH7.8OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu...
CVE-2026-62221MEDIUM5.4OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature...
CVE-2026-62220MEDIUM6.3OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit...
CVE-2026-62219HIGH7.1OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio...
CVE-2026-62218HIGH8.8OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha...
CVE-2026-62217HIGH8.8OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f...
CVE-2026-62216MEDIUM5OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or c...
CVE-2026-62215HIGH8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo...
CVE-2026-62214MEDIUM6.5OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t...
CVE-2026-62213MEDIUM6.5OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower...
CVE-2026-62212HIGH7.1OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now