Improper privilege management in OpenClaw - #VU132709

 

Improper privilege management in OpenClaw - #VU132709

Published: May 29, 2026


Vulnerability identifier: #VU132709
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain broader pending pairing authority than intended.

The vulnerability exists due to improper privilege management in the bootstrap token pairing feature when reusing a pending bootstrap token before approval with a broader requested scope set. A remote user can replay a pending bootstrap token with expanded requested scopes to retain broader pending pairing authority than intended.

Only instances where the affected feature is enabled and reachable are vulnerable.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.5.12

External References

Related Security Bulletins