CVE-2026-32905: OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClaw bundled device-pair pluginto a version that resolves this vulnerability.Fixed in 2026.5.4 - Compensating control
Manually remove any devices that were enrolled using bootstrap codes issued via the chat-command authorization bypass, since the enrollment provides persistent operator/node capabilities until manual removal.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32905?
The severity of CVE-2026-32905 is high with a score of 8.7.
How do I fix CVE-2026-32905?
To fix CVE-2026-32905, upgrade OpenClaw to version 2026.5.4 or later.
What type of vulnerability is CVE-2026-32905?
CVE-2026-32905 is an authorization bypass vulnerability allowing unauthorized device-pairing code issuance.
What impact does CVE-2026-32905 have on OpenClaw users?
CVE-2026-32905 allows non-owner authorized chat senders to issue device-pairing bootstrap codes, posing a risk to device security.
Who can exploit CVE-2026-32905?
Attackers with access to the chat command can exploit CVE-2026-32905 to create unauthorized setup codes for device enrollment.