Missing Authorization in OpenClaw - #VU135901
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to missing authorization in device.pair.approve when handling lower-trust caller requests or configured input paths. A remote user can invoke the affected feature through a reachable lower-trust path to bypass authorization checks.
Exploitation is possible only when the affected feature is enabled and reachable.