Junglewise Threat Intelligence

OpenClaw authorization bypass via pairing-scoped device session

Severity: high · CVSS 8.8 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an open-source communication library, contains a flaw that allows previously authorized devices to maintain access even after their permissions have been revoked. An attacker with an existing paired device can bypass security controls to regain full access to the system's communication channels without needing new approval from an administrator. This undermines the ability of operators to effectively kick unauthorized or compromised devices off the network.

Technical details

OpenClaw before version 2026.5.26 is vulnerable to an authorization bypass (CWE-613/CWE-863) due to insufficient session expiration. When a node token is revoked, the system fails to invalidate associated pairing-scoped device sessions. An attacker with a previously paired device can leverage these surviving sessions to re-authenticate and regain WebSocket node-level access without renewed administrative approval. This allows for persistent unauthorized access and bypasses intended device-role containment. The issue is resolved in version 2026.5.26; as a manual mitigation for older versions, administrators should restart the gateway and manually re-pair devices.

Affected products

  • OpenClaw openclaw < 2026.5.26

Timeline

  • 2026-05-28: advisory: Original advisory GHSA-q99w-vh6v-q3v7 published
  • 2026-06-16: disclosed: CVE-2026-53843 published to NVD
  • 2026-06-18: patched: Duplicate advisory withdrawn and patch confirmed in 2026.5.26

References

Related threats