CVE-2026-53843 Details
Description
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.
An authorization bypass vulnerability has been identified in OpenClaw versions prior to 2026.5.26. This vulnerability allows a device with a surviving pairing-scoped session to re-establish node token authority after it has been revoked. As a result, attackers with a paired device can regain WebSocket node-level access without needing renewed approval. This issue undermines revocation controls, allowing unauthorized access to persist longer than intended.
Users are advised to upgrade to OpenClaw version 2026.5.26 or later. If a node token was revoked in an earlier version, it is recommended to restart the gateway and remove or re-pair the affected device to ensure that no stale session remains active.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-q99w-vh6v-q3v7 | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-node-token-revocation-bypass-via-pairing-scoped-device-session | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.5.26 2026.5.26 beta1 2026.5.26 beta2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | New CVE Received | [email protected] |