Impact
OpenClaw versions prior to 2026.5.18 contain a flaw in the device‑pair approval feature that lets callers with lower trust levels perform actions they are not entitled to. The vulnerability is a classic example of improper authorization (CWE-863), enabling attackers to execute or persist unauthorized operations when the affected feature is turned on and reachable.
Affected Systems
The issue affects installations of OpenClaw, specifically any deployment running a node.js based OpenClaw instance before the 2026.5.18 release. No specific sub‑components are singled out in the advisory.
Risk and Exploitability
The flaw carries a CVSS score of 7.7, indicating high severity. The EPSS score is below 1 %, suggesting a low yet non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to identify a reachable device‑pair API endpoint and leverage misconfigured input handling to trigger the bypass; it is not stated whether public exploit code exists, but the attack vector is assumed to be local or remote network access to the affected API.
OpenCVE Enrichment