PT-2026-49769 · Openclaw · Openclaw
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.25
Description
A scope containment bypass exists in the device re-pairing process. Authenticated operators can restore or retain broader scopes than intended by submitting re-pairing requests with empty scope sets, which allows them to skip containment guards and maintain unauthorized device access. This issue occurs when the affected feature is enabled and reachable, though the practical impact depends on the operator's configuration and the accessibility of the path to lower-trust input.
Recommendations
Update to version 2026.4.25.
Revoke unexpected device sessions and require fresh pairing for suspicious devices.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the device re-pairing feature when it is not needed.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw