Junglewise Threat Intelligence

OpenClaw scope containment bypass in device re-pairing

Severity: low · CVSS 3.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a device pairing and access management platform used by operators to control gateway access scopes. A vulnerability in the device re-pairing function allows authenticated operators to circumvent scope restrictions by submitting empty-scope re-pairing requests, potentially restoring broader access than intended. This could result in unauthorized access retention or scope escalation for compromised devices.

Technical details

This is a scope containment bypass vulnerability in the device re-pairing logic affecting OpenClaw before version 2026.4.25. The root cause is insufficient validation of the scope parameter during re-pairing requests; an authenticated operator can send a re-pairing request with an empty scope set to skip the containment guard logic. The attack requires an authenticated operator with access to the affected re-pairing feature, which is network-reachable when enabled. An attacker can exploit this to restore or retain device scopes broader than the caller should be permitted to grant. The vulnerability is patched in version 2026.4.25; mitigation includes revoking unexpected device sessions and requiring fresh pairing for suspicious devices.

Affected products

  • OpenClaw OpenClaw <2026.4.25

Timeline

  • 2026-05-28: disclosed
  • 2026-06-16: advisory
  • 2026.4.25: patched: First stable patched version

References

Related threats