Authorization Bypass in OpenClaw Device Pairing Feature by OpenClaw
CVE-2026-62218

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62218?

The OpenClaw device.pair.approve functionality is vulnerable to an authorization bypass, allowing lower-privilege users to sidestep role-management validations. This could enable unauthorized actions that typically require higher authorization levels, by exploiting established input paths. It's crucial for users to address this security flaw by updating to version 2026.5.27 or later to mitigate potential risks associated with this vulnerability.

Affected Version(s)

OpenClaw 2026.1.20 < 2026.5.27

OpenClaw 2026.5.27

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.