Junglewise Threat Intelligence

OpenClaw pending pairing-request cap enforcement bypass

Severity: low · CVSS 3.1 · Published 2026-04-24

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software component that handles secure pairing and authentication flows. A vulnerability in versions 2026.2.26 through 2026.3.30 incorrectly enforces limits on pending pairing requests at the channel level rather than per user account. An attacker can exploit this by submitting multiple pairing requests across different accounts, exhausting the shared limit and preventing legitimate users from setting up new accounts or devices, causing a denial of service.

Technical details

OpenClaw enforces caps on pending pairing requests to prevent abuse, but versions 2026.2.26 through 2026.3.30 incorrectly scope these limits to the channel file rather than to individual accounts. This allows a remote, unauthenticated attacker to submit pairing requests from multiple accounts to exhaust the shared pending window. By flooding the cap with requests from attacker-controlled accounts, an attacker can block new pairing challenges on victim accounts, causing a denial of service during pairing setup. The vulnerability is availability-only and does not enable cross-account approval, data access, or authorization bypass. The fix, released in OpenClaw 2026.3.31, properly scopes pending request caps per account.

Affected products

  • OpenClaw openclaw >= 2026.2.26, < 2026.3.31

Timeline

  • 2026-04-02: disclosed
  • 2026-03-31: patched
  • 2026-04-24: advisory

References

Related threats