CVE 8.3 HIGH

OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command_CVE-2026-32905

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Description

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.

Basic Information

ID CVE-2026-32905
Source VulnCheck
Published May 29, 2026 at 15:09
Modified May 29, 2026 at 15:13

Affected Product

Vendor OpenClaw
Product OpenClaw
Affected Versions OpenClaw OpenClaw 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.