PT-2026-49760 · Openclaw · Openclaw

·

CVE-2026-53843

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.26
Description An authorization bypass exists where a surviving pairing-scoped device session can re-establish node token authority after the token has been revoked. This allows a previously paired device to regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended. This issue specifically affects token revocation and device-role containment but does not allow the creation of unauthenticated devices.
Recommendations Update to version 2026.5.26 or later. If a node token was revoked on a version prior to 2026.5.26, restart the gateway and remove or re-pair the affected device to ensure no stale session remains active.

Exploit

Fix

Insufficient Session Expiration

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53843
GHSA-Q99W-VH6V-Q3V7
GHSA-WRMQ-9FC4-GWWJ

Affected Products

Openclaw