Executive brief
OpenClaw is a device pairing and access management platform used by operators to control gateway access scopes. A vulnerability in the device re-pairing function allows authenticated operators to circumvent scope restrictions by submitting empty-scope re-pairing requests, potentially restoring broader access than intended. This could result in unauthorized access retention or scope escalation for compromised devices.
Technical details
This is a scope containment bypass vulnerability in the device re-pairing logic affecting OpenClaw before version 2026.4.25. The root cause is insufficient validation of the scope parameter during re-pairing requests; an authenticated operator can send a re-pairing request with an empty scope set to skip the containment guard logic. The attack requires an authenticated operator with access to the affected re-pairing feature, which is network-reachable when enabled. An attacker can exploit this to restore or retain device scopes broader than the caller should be permitted to grant. The vulnerability is patched in version 2026.4.25; mitigation includes revoking unexpected device sessions and requiring fresh pairing for suspicious devices.
Affected products
- OpenClaw OpenClaw <2026.4.25
Timeline
- 2026-05-28: disclosed
- 2026-06-16: advisory
- 2026.4.25: patched: First stable patched version