PT-2026-49779 · Openclaw · Openclaw

·

CVE-2026-53862

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.12
Description A bootstrap token replay issue allows callers with access to a pending bootstrap token to reuse it before approval with a broader requested scope. This can lead to the escalation of pairing authority beyond the intended scope limits. The impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Recommendations Update to version 2026.5.12. Treat pairing codes as sensitive and cancel unexpected pending pairings. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the bootstrap token feature when it is not needed.

Exploit

Fix

Improper Privilege Management

Insufficient Verification of Data Authenticity

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53862
GHSA-9V8J-9C9G-W66C
GHSA-H9H6-PWQV-J9HV

Affected Products

Openclaw