SB2026052911 - Multiple vulnerabilities in OpenClaw
Published: May 29, 2026 Updated: June 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Authentication Bypass by Spoofing (CVE-ID: N/A)
CWE-ID: CWE-290 - Authentication Bypass by Spoofing
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to obtain a durable admin-capable device token.
The vulnerability exists due to authentication bypass by spoofing in the Control UI pairing path when processing locality information during pairing. A remote user can spoof locality information to obtain a durable admin-capable device token.
This issue is limited to LAN or shared-token Control UI deployments where the caller already has the network and authentication foothold needed to reach the pairing path.
2) Inclusion of Functionality from Untrusted Control Sphere (CVE-ID: N/A)
CWE-ID: CWE-829 - Inclusion of Functionality from Untrusted Control Sphere
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute or persist actions beyond the caller's intended authorization.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in setup-mode discovery workspace plugins when processing a configured input path or lower-trust caller-controlled workspace input. A remote attacker can provide a crafted workspace plugin path or plugin input to execute or persist actions beyond the caller's intended authorization.
Only instances where the affected feature is enabled and reachable are vulnerable, and user interaction is required.
Remediation
Install update from vendor's website.