CVE-2026-53838 Details
Description
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.
A state mutation vulnerability has been identified in OpenClaw versions prior to 2026.5.27. This vulnerability occurs in the node pairing reconnection process, allowing paired nodes to manipulate approval scope decisions. Exploitation of the reconnection logic can result in broader node authority being presented or restored, potentially bypassing established approval restrictions.
To address this vulnerability, revoke any unexpected node pairings and re-pair only trusted nodes until the patch is applied. As a general precaution, maintain narrow channel and tool allowlists, avoid sharing a single Gateway between untrusted users, and disable the affected feature when it is not in use.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-83w9-h5wv-j9xm | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-node-pairing-state-mutation-via-reconnection | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.5.27 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 12, 2026 | New CVE Received | [email protected] |