


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 18:02:16
Source:
nvd.nist.gov
Identity & Access, Mobile & IoT
OpenClaw versions before 2026.5.4 contain a critical authorization bypass vulnerability in the device-pair plugin. The flaw allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can exploit this to create setup codes for enrolling devices with elevated operator/node capabilities. This grants persistent unauthorized credentials that remain active until manual removal by administrators. The vulnerability affects the bundled device-pair plugin and represents a significant security risk for OpenClaw deployments.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32905
https://github.com/openclaw/openclaw/security/advisories/GHSA-xr4f-mjxj-w6w5
https://www.vulncheck.com/advisories/openclaw-unauthorized-device-pairing-bootstrap-code-issuance-via-chat-command
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
