PT-2026-44891 · Openclaw · Device-Pair Plugin+1

·

CVE-2026-32905

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.4
Description An authorization bypass exists in the bundled device-pair plugin. This issue allows non-owner authorized chat senders to issue device-pairing bootstrap codes because the system fails to perform proper scope validation. Attackers with chat command access can generate setup codes to enroll devices with operator or node capabilities, which provides them with persistent credentials until the devices are manually removed.
Recommendations Update to version 2026.5.4 or later.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32905
GHSA-XR4F-MJXJ-W6W5

Affected Products

Openclaw
Device-Pair Plugin