Junglewise Threat Intelligence

OpenClaw privilege escalation via bootstrap token replay

Severity: medium · CVSS 4.2 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a gateway and integration tool used for connecting different software services. A security flaw allows an attacker to reuse temporary setup tokens to request higher levels of access than originally intended. If successful, an attacker could gain broader control over the system's integrations before an administrator approves the connection.

Technical details

OpenClaw versions prior to 2026.5.12 are vulnerable to a bootstrap token replay attack. The vulnerability exists in the pairing mechanism where a caller with access to a pending bootstrap token can reuse that token to request a broader set of scopes than initially defined. Because the system does not sufficiently verify the authenticity or integrity of the token's scope during the pending state, an attacker can escalate their privileges before the pairing is finalized by an operator. This requires the attacker to have network access to the gateway and for the bootstrap feature to be enabled. The issue is addressed in version 2026.5.12.

Affected products

  • openclaw openclaw < 2026.5.12

Timeline

  • 2026-05-28: advisory: Original GHSA-9v8j-9c9g-w66c published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53862
  • 2026-06-18: patched: Duplicate advisory withdrawn and patch confirmed in 2026.5.12

References

Related threats