Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 18, 2026
OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
CVE-2026-62218
Description
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-8v95-qqcm-qp9hmitrevendor-advisory
- www.vulncheck.com/advisories/openclaw-authorization-bypass-via-device-pair-approvemitrethird-party-advisory
News mentions
0No linked articles in our index yet.