PT-2026-49760 · Openclaw · Openclaw
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.26
Description
An authorization bypass exists where a surviving pairing-scoped device session can re-establish node token authority after the token has been revoked. This allows a previously paired device to regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended. This issue specifically affects token revocation and device-role containment but does not allow the creation of unauthenticated devices.
Recommendations
Update to version 2026.5.26 or later.
If a node token was revoked on a version prior to 2026.5.26, restart the gateway and remove or re-pair the affected device to ensure no stale session remains active.
Exploit
Fix
Insufficient Session Expiration
Improper Access Control
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw