Junglewise Threat Intelligence

CVE-2026-41909: OpenClaw paired-device authorization bypass

CVE-2026-41909 · Severity: medium · CVSS 4 · Published 2026-04-25

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an IoT device management platform that coordinates pairing between multiple devices. A paired device with limited permissions could improperly access and act on pairing requests intended for other devices within the same gateway. An attacker with a limited paired-device session could enumerate and approve device pairing requests that don't belong to them, potentially allowing unauthorized device enrollment.

Technical details

A paired-device session with restricted pairing scope could enumerate global pairing state and approve or operate on pending device pairing requests that belonged to other devices within the same gateway. The vulnerability stems from improper authorization checks in pairing management actions (CWE-284 and CWE-863), where device scope was not correctly enforced. Attack preconditions include having a valid paired-device session with limited privileges and network access to the gateway. The impact allows a non-admin paired device to approve unrelated pending device requests, potentially leading to unauthorized device enrollment. The fix, released in OpenClaw 2026.4.20, now restricts pairing management actions to only the caller device.

Affected products

  • OpenClaw OpenClaw < 2026.4.20

Timeline

  • 2026-04-25: disclosed
  • 2026-04-25: patched: Fixed in version 2026.4.20 with commit 5a12f30441d5b0b151f550daa2c5c9e8db61e2e6

References

Related threats