Impact
The vulnerability is located in the device.pair.approve feature of OpenClaw. It allows callers with lower trust levels to bypass role‑management checks, effectively granting them privileges that should be restricted. Exploitation of this flaw can lead to unauthorized execution of actions that require higher authorization, compromising confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑862: Missing Authorization.
Affected Systems
The affected product is OpenClaw software distributed by OpenClaw. Versions prior to 2026.5.27, including 2026.1.20 and subsequent releases up to but excluding 2026.5.27 are vulnerable. The application is built on a Node.js environment as reflected by the CPE entry.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, but the EPSS score reads less than 1%, suggesting a low current likelihood of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is via the device.pair.approve endpoint through normal input paths, likely over a network connection, and requires a lower‑trust caller context. While the impact is significant, the low EPSS and lack of exploitation evidence temper immediate risk, yet authorities should treat it as a high‑impact issue until mitigated.
OpenCVE Enrichment