


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:07
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access
OpenClaw versions before 2026.5.4 contain an authorization bypass vulnerability in the device-pair plugin. The flaw allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can exploit this to create setup codes for enrolling devices with operator/node capabilities. This grants persistent credentials that remain active until manually removed. The vulnerability affects the bundled device-pair plugin and represents a significant authorization control failure.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32905
https://github.com/openclaw/openclaw/security/advisories/GHSA-xr4f-mjxj-w6w5
https://www.vulncheck.com/advisories/openclaw-unauthorized-device-pairing-bootstrap-code-issuance-via-chat-command
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
