Executive brief
OpenClaw, a tool used for managing device control interfaces, contains a flaw in how it verifies the location of devices during the pairing process. An attacker who already has basic access to the local network can trick the system into granting them a permanent administrator-level token. This allows the attacker to maintain long-term control over the system even after temporary access credentials have been changed.
Technical details
A vulnerability in OpenClaw's Control UI pairing mechanism allows for locality spoofing (CWE-290). In configurations where locality signals (such as being on a specific LAN) are used as a primary trust factor for pairing, an attacker with an existing network foothold can spoof these signals to successfully pair a device. This results in the creation of a durable, admin-capable device token that persists even after shared gateway tokens are rotated. The issue stems from improper validation of locality-derived trust during the pairing handshake. A fix is available in version 2026.5.22.
Affected products
- OpenClaw openclaw < 2026.5.22
Timeline
- 2026-05-28: disclosed
- 2026-05-28: patched: First stable patched version 2026.5.22 released
- 2026-06-11: advisory: NVD publication
- 2026-07-02: advisory: GitHub Advisory reviewed