Authorization Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-53843
8.7HIGH
What is CVE-2026-53843?
OpenClaw versions prior to 2026.5.26 are subject to an authorization bypass vulnerability whereby an existing pairing-scoped device session can re-establish node token authority post-revocation. This flaw permits attackers with a paired device to regain unauthorized WebSocket node-level access without the necessity for renewed authorization. Consequently, the effectiveness of revocation controls is compromised, effectively extending unauthorized access beyond intended limits.
Affected Version(s)
OpenClaw 0 < 2026.5.26
OpenClaw 2026.5.26
