CVE-2026-53817: OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing

Published Jun 11, 2026
·
Updated

Summary

In affected LAN/shared-token Control UI deployments, a caller could spoof locality information used during Control UI pairing and obtain a durable admin-capable device token.

This issue is limited to deployments where the caller already has the network/authentication foothold needed to reach the Control UI pairing path. It is not an unauthenticated internet exposure issue.

Affected configurations

This affects configurations such as LAN-bound gateways or shared-token Control UI access where locality signals were accepted as sufficient for pairing decisions.

Impact

A temporary or shared Control UI access path could be turned into a persistent admin device token. That token could remain useful after the shared gateway token was rotated, unless the paired device was removed.

The issue is a pairing/locality validation problem: locality-derived trust was stronger than it should have been.

Patched Versions

The first stable patched version is 2026.5.22.

Mitigations

Upgrade to openclaw@2026.5.22 or later. For older deployments, remove unexpected paired devices and avoid exposing Control UI pairing paths on networks with untrusted clients.

Other sources

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.

NVD

Affected Software

3 affected componentsFixes available
OpenClaw<2026.5.22
OpenClaw Openclaw Node.js<2026.5.22
npm/openclaw<2026.5.22
2026.5.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.5.22
  2. Upgrade

    Upgrade openclaw to a version that resolves this vulnerability.

    Fixed in 2026.5.22
  3. Compensating control

    For older deployments, remove unexpected paired devices and avoid exposing Control UI pairing paths on networks with untrusted clients.

Event History

Jun 11, 2026
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Jul 2, 2026
Advisory Published
via GitHub·04:04 PM
Data Sourced
via GitHub·04:04 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-53817?

CVE-2026-53817 has a high severity score of 8.8.

2

How can I fix CVE-2026-53817?

To fix CVE-2026-53817, upgrade OpenClaw to version 2026.5.22 or later.

3

What type of vulnerability is CVE-2026-53817?

CVE-2026-53817 is a locality validation vulnerability in Control UI pairing.

4

What is the risk associated with CVE-2026-53817?

The risk level for CVE-2026-53817 is rated at 79, which indicates a significant vulnerability.

5

Who is affected by CVE-2026-53817?

Any users of OpenClaw versions prior to 2026.5.22 are affected by CVE-2026-53817.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203