Executive brief
OpenClaw is an AI automation platform that manages user access through device pairing and role-based permissions. A vulnerability allows an attacker with access to the shared authentication token to present an unpaired device identity and claim elevated administrator privileges without completing the required device pairing approval process. This could let an unauthorized actor gain full administrative control over the OpenClaw gateway and the systems it manages.
Technical details
The vulnerability is an incorrect authorization check (CWE-863) in OpenClaw's gateway authentication logic. When a client authenticates using shared token/password auth, the gateway fails to enforce device pairing requirements before allowing elevation to operator scopes. An attacker can present a self-signed, unpaired device identity and request elevated permissions (up to operator.admin level) without waiting for pairing approval. The attack requires valid shared gateway authentication credentials but does not require the device to be previously paired or approved. The fix (released in version 2026.2.25) requires that operator device-identity sessions using shared token auth must complete pairing before operator scopes can be assigned, with exceptions only for control-ui trusted-proxy bypass paths.
Affected products
- OpenClaw openclaw >= 2026.2.22, <= 2026.2.24
Timeline
- 2026-03-03: disclosed: Advisory published
- 2026-02-26: patched: Fix committed; released in version 2026.2.25