Openclaw · Openclaw · CVE-2026-53852
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.4.25
**Description**
A scope containment bypass exists in the device re-pairing process. Authenticated operators can restore or retain broader scopes than intended by submitting re-pairing requests with empty scope sets, which allows them to skip containment guards and maintain unauthorized device access. This issue occurs when the affected feature is enabled and reachable, though the practical impact depends on the operator's configuration and the accessibility of the path to lower-trust input.
**Recommendations**
Update to version 2026.4.25.
Revoke unexpected device sessions and require fresh pairing for suspicious devices.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the device re-pairing feature when it is not needed.