Executive brief
OpenClaw, a node management and gateway tool, contains a flaw in how it handles reconnecting devices. An attacker can exploit this to trick the system into granting a device more authority or access permissions than originally intended. This could allow unauthorized actions or access to restricted data within the network.
Technical details
A state mutation vulnerability exists in OpenClaw's node pairing reconnection logic, classified as a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367). When a paired node reconnects, it can manipulate the session state to bypass approval restrictions or escalate its authorized scope. This allows a node to present or restore broader authority than originally granted by the operator. The vulnerability is reachable over the network and, while some sources suggest it requires low privileges, others indicate it can be exploited to gain high impact on integrity and confidentiality. The issue is resolved in version 2026.5.27.
Affected products
- OpenClaw OpenClaw < 2026.5.27
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-05-27: patched: Version 2026.5.27 released
- 2026-06-12: disclosed: NVD publication date