PT-2026-35771 · Openclaw · Openclaw
Tdjackey
·
Published
2026-04-03
·
Updated
2026-05-12
·
CVE-2026-41386
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
An issue exists where bootstrap setup codes are not bound to intended device roles and scopes during pairing. This allows attackers to escalate privileges beyond their intended role and scope during first-use device pairing.
Recommendations
Update to version 2026.3.22.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw