Authorization Bypass in OpenClaw Device Pairing Feature by OpenClaw
CVE-2026-62218
8.7HIGH
What is CVE-2026-62218?
The OpenClaw device.pair.approve functionality is vulnerable to an authorization bypass, allowing lower-privilege users to sidestep role-management validations. This could enable unauthorized actions that typically require higher authorization levels, by exploiting established input paths. It's crucial for users to address this security flaw by updating to version 2026.5.27 or later to mitigate potential risks associated with this vulnerability.
Affected Version(s)
OpenClaw 2026.1.20 < 2026.5.27
OpenClaw 2026.5.27
