CVE-2026-62218: OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.27
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62218?
The severity of CVE-2026-62218 is rated high, with a score of 8.7.
How do I fix CVE-2026-62218?
To fix CVE-2026-62218, update OpenClaw to version 2026.5.27 or later.
What exploit does CVE-2026-62218 represent?
CVE-2026-62218 represents an authorization bypass vulnerability that allows lower-trust callers to bypass role-management checks.
Which versions of OpenClaw are affected by CVE-2026-62218?
OpenClaw versions 2026.1.20 up to 2026.5.26 are affected by CVE-2026-62218.
What actions can attackers perform due to CVE-2026-62218?
Attackers can perform actions requiring stronger authorization by exploiting the vulnerability in the device.pair.approve feature.