VYPR
Medium severity4.2NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-53862

CVE-2026-53862

Description

OpenClaw before 2026.5.12 allows bootstrap token replay, enabling attackers with pending token access to escalate pairing authority beyond intended scope.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenClaw before 2026.5.12 allows bootstrap token replay, enabling attackers with pending token access to escalate pairing authority beyond intended scope.

Vulnerability

OpenClaw before version 2026.5.12 contains a bootstrap token replay vulnerability [1][2]. When the affected feature is enabled, a caller with access to a pending bootstrap token can reuse that token before approval with a broader requested scope set. This allows the caller to request more extensive pairing permissions than originally intended.

Exploitation

An attacker must have access to a pending bootstrap token, which could occur through network access or local user interaction. The attacker then replays the token with a broader requested scope before the approval process completes, effectively escalating the pairing authority. The CVSS vector indicates the attack complexity is high and requires user interaction ([2]).

Impact

Successful exploitation can present or retain broader pending pairing authority than intended, potentially leading to unauthorized pairing operations. The impact is limited to confidentiality and integrity at a low level, with no availability impact ([2]). Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.

Mitigation

The vulnerability is fixed in OpenClaw version 2026.5.12 [1]. As a workaround, treat pairing codes as sensitive and cancel unexpected pending pairings until patched. Additional mitigations include keeping channel and tool allowlists narrow, avoiding sharing a Gateway between mutually untrusted users, and disabling the affected feature when not needed [1].

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.