CVE-2026-41386: OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
Published Apr 28, 2026
·Updated
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.
Affected Software
2 affected components
OpenClaw OpenClaw<2026.3.22
OpenClaw Openclaw Node.js<2026.3.22
Remediation
Event History
Apr 28, 2026
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:37 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-41386?
CVE-2026-41386 is classified as a high severity privilege escalation vulnerability.
2
How do I fix CVE-2026-41386?
To mitigate CVE-2026-41386, upgrade OpenClaw to version 2026.3.22 or later.
3
What impact does CVE-2026-41386 have on my system?
CVE-2026-41386 allows attackers to gain unauthorized access and escalate privileges on affected devices.
4
How does CVE-2026-41386 exploit the system?
CVE-2026-41386 exploits weak binding of bootstrap setup codes to device roles during the initial pairing.
5
Which versions of OpenClaw are affected by CVE-2026-41386?
OpenClaw versions prior to 2026.3.22 are affected by CVE-2026-41386.