Openclaw · Openclaw · CVE-2026-53843
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.5.26
**Description**
An authorization bypass exists where a surviving pairing-scoped device session can re-establish node token authority after the token has been revoked. This allows a previously paired device to regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended. This issue specifically affects token revocation and device-role containment but does not allow the creation of unauthenticated devices.
**Recommendations**
Update to version 2026.5.26 or later.
If a node token was revoked on a version prior to 2026.5.26, restart the gateway and remove or re-pair the affected device to ensure no stale session remains active.