CVE-2026-53852
EUVD-2026-3715416.06.2026, 19:17
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 𝑥 < 2026.4.25 |
| openclaw | openclaw | 2026.4.25:beta1 |
| openclaw | openclaw | 2026.4.25:beta10 |
| openclaw | openclaw | 2026.4.25:beta11 |
| openclaw | openclaw | 2026.4.25:beta2 |
| openclaw | openclaw | 2026.4.25:beta3 |
| openclaw | openclaw | 2026.4.25:beta4 |
| openclaw | openclaw | 2026.4.25:beta5 |
| openclaw | openclaw | 2026.4.25:beta6 |
| openclaw | openclaw | 2026.4.25:beta7 |
| openclaw | openclaw | 2026.4.25:beta8 |
| openclaw | openclaw | 2026.4.25:beta9 |
𝑥
= Vulnerable software versions