Improper privilege management in OpenClaw - CVE-2026-41386
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in bootstrap setup code handling when pairing a device for first use. A remote attacker can use a setup code not bound to the intended device role and scopes to escalate privileges.
The issue occurs during first-use pairing.