GHSA-4cxx-m26f-jmx8HighCVSS 8.8
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device...
🔗 CVE IDs covered (1)
📋 Description
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.