OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | npm/openclaw: < 2026.5.26 |
Updated severity to CRITICAL, added affected version 2026.5.25, and noted that no exploit is available.
Initial creation