Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3135 articles · 161991 vulns · 38/41 feeds (7d)
← Back to list
8.3
CVE-2026-32905EXPLOITEDPATCHED
openclaw · openclaw

OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command

Description

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.

Affected Products

VendorProductVersions
openclawopenclaw0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopenclawcert_advisory90%

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-xr4f-mjxj-w6w5(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-unauthorized-device-pairing-bootstrap-code-issuance-via-chat-command(third-party-advisory)

Related News (2 articles)

Tier B
BSI Advisories9d ago
[NEU] [hoch] OpenClaw: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-32905 | OpenClaw up to 2026.5.3 authorization (GHSA-xr4f-mjxj-w6w5)
→ No new info (linked only)
CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2026.5.4
CWECWE-862
PublishedMay 29, 2026
Last enriched11d agov2
Trending Score16
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-35630EXP
OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons
Trending: 9
HIGHCVE-2026-35674EXP
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
Trending: 9
CRITICALCVE-2026-34507EXP
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
Trending: 8
NONECVE-2026-32906EXP
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
Trending: 6
MEDIUMCVE-2026-35673
OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 29, 2026
Discovered by ZDM
May 29, 2026
Updated: affectedVersions, severity, activelyExploited
May 29, 2026
Actively Exploited
May 29, 2026
Patch Available
May 29, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated affected versions to include 2026.5.3, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploited
via VulDB
v111d ago

Initial creation