Authentication Bypass by Spoofing in OpenClaw - #VU132707

 

Authentication Bypass by Spoofing in OpenClaw - #VU132707

Published: May 29, 2026


Vulnerability identifier: #VU132707
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-290
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain a durable admin-capable device token.

The vulnerability exists due to authentication bypass by spoofing in the Control UI pairing path when processing locality information during pairing. A remote user can spoof locality information to obtain a durable admin-capable device token.

This issue is limited to LAN or shared-token Control UI deployments where the caller already has the network and authentication foothold needed to reach the pairing path.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.5.22

External References

Related Security Bulletins