Junglewise Threat Intelligence

CVE-2026-42422: OpenClaw device.token.rotate authorization bypass

CVE-2026-42422 · Severity: low · CVSS 3.1 · Published 2026-04-09

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a local AI assistant framework that manages user-controlled device permissions through a token rotation mechanism. A flaw in the device.token.rotate function allows an attacker to mint authentication tokens for roles that were never approved through the intended authorization process, effectively bypassing security controls that should restrict what permissions a device can hold. This allows unauthorized privilege escalation within the local trust boundary.

Technical details

The vulnerability is an incorrect authorization check (CWE-863) in the device.token.rotate function of OpenClaw. During token rotation, the system mints or preserves roles and scopes without verifying they passed through the required role-upgrade pairing approval process. An attacker with local access can invoke token rotation to obtain tokens granting unapproved roles. The attack requires no network access and assumes the attacker has local control of the OpenClaw instance. The vulnerability is fixed in version 2026.4.8 (commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5).

Affected products

  • OpenClaw openclaw <= v2026.04.01

Timeline

  • 2026-04-09: disclosed
  • 2026-04-08: patched: Fix available in npm version 2026.4.8

References

Related threats