CVE-2026-32987: OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32987?
CVE-2026-32987 is classified as a high severity vulnerability due to its potential to allow unauthorized access through repeated verification of bootstrap setup codes.
How do I fix CVE-2026-32987?
To fix CVE-2026-32987, upgrade OpenClaw to version 2026.3.13 or later to mitigate the vulnerability.
What impact does CVE-2026-32987 have on device security?
CVE-2026-32987 can lead to unauthorized access as attackers can exploit replayed bootstrap setup codes during pairing verification.
Who is affected by CVE-2026-32987?
CVE-2026-32987 affects all users of OpenClaw prior to version 2026.3.13.
What version of OpenClaw should I upgrade to for protection against CVE-2026-32987?
You should upgrade to OpenClaw version 2026.3.13 or later to protect against CVE-2026-32987.