Incorrect authorization in OpenClaw - #VU132735
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to enroll a device with operator or node capabilities.
The vulnerability exists due to improper access control in the bundled device-pair plugin /pair endpoint when handling normal chat command requests. A remote user can issue a device-pairing bootstrap code to enroll a device with operator or node capabilities.
This issue affects deployments where the bundled device-pair plugin is enabled, and the enrolled device retains persistent credentials until removed.