Junglewise Threat Intelligence

CVE-2026-53852: OpenClaw scope containment bypass in device re-pairing

CVE-2026-53852 · Severity: medium · CVSS 5.4 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing device gateways, contains a flaw in how it handles device re-pairing. An attacker could potentially bypass security restrictions to gain broader access permissions than intended. This could lead to unauthorized access to sensitive data or system functions depending on the specific configuration.

Technical details

A vulnerability exists in OpenClaw (npm package) where a device re-pairing request containing an empty scope set fails to trigger intended containment guards. This is a 'Failing Open' (CWE-636) issue where the system defaults to a less restrictive state when an empty scope is provided. An authenticated attacker with network access can exploit this during the re-pairing process to retain or restore scopes broader than those typically granted to the caller. The vulnerability is patched in version 2026.4.25.

Affected products

  • openclaw openclaw <= 2026.4.24

Timeline

  • 2026-05-28: disclosed
  • 2026-06-18: advisory
  • 2026.4.25: patched

References

Related threats