Executive brief
OpenClaw is an automation agent that can be controlled via chat platforms like Telegram, Discord, and Slack. A security flaw in its device-pairing plugin allows users who are authorized to send basic chat commands to also generate device-pairing codes. An attacker could use this to link their own unauthorized device to the system with full administrative or operator privileges, potentially leading to long-term unauthorized access and control over the environment.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the bundled device-pair plugin of OpenClaw. The `/pair` command was incorrectly exposed on normal chat command surfaces, allowing any authorized chat sender to generate bootstrap codes regardless of their specific permission scope (owner, admin, or pairing). An attacker with basic chat access can generate a setup code and enroll a new device with operator/node capabilities, gaining persistent credentials. This affects deployments using Telegram, Discord, or Slack agents where non-owner users have command access. The issue is resolved in version 2026.5.4.
Affected products
- openclaw openclaw < 2026.5.4
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory
- 2026-05-28: patched: First stable patched version 2026.5.4