Back

HIGH

OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command

Published May 29, 2026

Description

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 29, 2026
Updated Sep 24, 2026
Reserved Mar 16, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Analyzed
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a