Description
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
Published: 2026-07-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the device.pair.approve feature of OpenClaw. It allows callers with lower trust levels to bypass role‑management checks, effectively granting them privileges that should be restricted. Exploitation of this flaw can lead to unauthorized execution of actions that require higher authorization, compromising confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑862: Missing Authorization.

Affected Systems

The affected product is OpenClaw software distributed by OpenClaw. Versions prior to 2026.5.27, including 2026.1.20 and subsequent releases up to but excluding 2026.5.27 are vulnerable. The application is built on a Node.js environment as reflected by the CPE entry.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, but the EPSS score reads less than 1%, suggesting a low current likelihood of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is via the device.pair.approve endpoint through normal input paths, likely over a network connection, and requires a lower‑trust caller context. While the impact is significant, the low EPSS and lack of exploitation evidence temper immediate risk, yet authorities should treat it as a high‑impact issue until mitigated.

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw 2026.5.27 or later.
  • Configure role‑based access control to enforce proper authorization on the approve endpoint.
  • Restrict or disable the device.pair.approve endpoint for lower‑trust callers until the patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
Title OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-862
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T03:55:34.111Z

Reserved: 2026-07-13T16:39:44.419Z

Link: CVE-2026-62218

cve-icon Vulnrichment

Updated: 2026-07-17T14:15:46.681Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses