CVE-2026-53817

HIGH

OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
GitHub Security Advisory (GHSA-chr9-m4q2-76hw)
https://github.com/openclaw/openclaw/security/advisories/GHSA-chr9-m4q2-76hw

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (3)
OpenClaw/OpenClaw < 2026.5.22
openclaw/openclaw < 2026.5.22
OpenClaw/OpenClaw 2026.5.22
Published Jun 11, 2026
Tracked Since Jun 12, 2026