PT-2026-49779 · Openclaw · Openclaw

Edward-X

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53862

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.

Fix

Incorrect Privilege Assignment

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2026-53862

Affected Products

Openclaw