Junglewise Threat Intelligence

CVE-2026-62218: OpenClaw authorization bypass in device.pair.approve

CVE-2026-62218 · Severity: high · CVSS 8.8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an open-source automation or gateway platform, contains a security flaw in its device pairing approval process. This vulnerability allows users with low-level access to bypass security checks and perform administrative actions they should not be authorized to do. If exploited, an attacker could gain full control over the system, potentially leading to data theft or service disruption.

Technical details

An authorization bypass vulnerability exists in OpenClaw's 'device.pair.approve' feature due to missing or improper authorization checks (CWE-862, CWE-269). The flaw allows an authenticated attacker with low privileges to bypass role-management restrictions by reaching the affected feature through specific input paths. Successful exploitation enables the attacker to perform actions requiring higher authorization levels, potentially leading to a full compromise of confidentiality, integrity, and availability. The issue is resolved in version 2026.5.27. As a mitigation, users are advised to restrict the affected feature to trusted operators or disable it entirely if not required.

Affected products

  • OpenClaw OpenClaw >= 2026.1.20, < 2026.5.27

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date
  • 2026-05-27: patched: First stable patched version released

References

Related threats