CVE-2026-53862: OpenClaw Bootstrap Token Replay Vulnerability – Scope Escalation Risk
OpenClaw versions before 2026.5.12 allow attackers to replay bootstrap tokens used during device pairing setup. An attacker who intercepts or obtains a pending bootstrap token can reuse it to request broader permissions than the token's original scope allowed, effectively escalating their access during the pairing process. This vulnerability requires the attacker to have network access and for a user to interact with the malicious request, but it can lead to unauthorized authority being granted to a paired device.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.2 MEDIUM · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-266, CWE-345
- Affected products
- 9 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-17
NVD description (verbatim)
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-53862 is a bootstrap token replay vulnerability in OpenClaw's authentication mechanism. The vulnerability stems from insufficient token validation and scope enforcement during the bootstrap pairing handshake. Attackers can capture a bootstrap token in a pending state and replay it with modified scope parameters to circumvent authorization boundaries. The issue affects token lifecycle management and permission escalation controls, allowing scope elevation beyond what the legitimate token holder intended. This maps to CWE-266 (Improper Privilege Assignment) and CWE-345 (Insufficient Verification of Data Authenticity).
Business impact
Compromise of OpenClaw pairing authority can enable unauthorized devices to integrate into protected environments with elevated permissions. This may allow attackers to establish persistent access, exfiltrate data from paired systems, or perform lateral movement within networks relying on OpenClaw for device orchestration. The impact depends on what systems are paired and what actions those permissions permit. Organizations using OpenClaw for critical infrastructure or sensitive data protection should treat this as a priority.
Affected systems
OpenClaw releases prior to version 2026.5.12 are affected. Organizations should verify their current OpenClaw deployment version against the vendor's advisory to confirm exposure. The vulnerability is present in the bootstrap token handling code path, affecting any OpenClaw instance that performs device pairing operations.
Exploitability
The vulnerability has a CVSS score of 4.2 (Medium severity) with a network attack vector, but requires both network access and user interaction to trigger. An attacker cannot exploit this passively; they must intercept a bootstrap token and trick a user into approving a malicious pairing request using the replayed token. The attack complexity is high, limiting widespread exploitation. However, targeted attacks against organizations that regularly pair new OpenClaw devices remain feasible. The vulnerability is not yet tracked on the CISA Known Exploited Vulnerabilities catalog.
Remediation
Upgrade to OpenClaw version 2026.5.12 or later. This release includes fixes to token validation and scope enforcement during bootstrap operations. Organizations unable to upgrade immediately should restrict OpenClaw pairing operations to trusted networks and implement network segmentation to limit exposure. Audit existing paired devices and revoke any pairing sessions established by untrusted parties.
Patch guidance
Apply OpenClaw version 2026.5.12 or later to all affected systems. The patch updates the bootstrap token verification logic to prevent replay attacks and enforces stricter scope validation. Test the update in a non-production environment first to ensure compatibility with existing paired devices. After patching, monitor pairing logs for evidence of failed or suspicious token replay attempts.
Detection guidance
Monitor OpenClaw logs for multiple failed bootstrap token validation errors within a short timeframe, which may indicate replay attempts. Check for bootstrap tokens being reused with different requested scopes than their original intent. Examine device pairing audit logs for unexpected privilege escalations or unauthorized pairing by devices with unfamiliar identifiers. Network-level detection should focus on identifying repeated bootstrap handshake attempts from the same source with varying parameters.
Why prioritize this
Although this vulnerability carries a Medium CVSS score, it should be prioritized based on your organization's reliance on OpenClaw for critical infrastructure or multi-tenancy boundaries. The requirement for user interaction and high attack complexity reduce the urgency compared to critical vulnerabilities, but scope escalation during pairing can grant persistent, privileged access that is difficult to revoke. Organizations managing large numbers of OpenClaw-paired devices or those in regulated industries should treat patching as soon as feasible within their change management windows.
Risk score, explained
The CVSS 3.1 score of 4.2 reflects a network-accessible vulnerability with user interaction and high complexity, resulting in low impact to confidentiality and integrity with no availability impact. The score does not capture the contextual severity for organizations where device pairing controls are critical to security boundaries; your internal risk assessment should account for the sensitivity of systems behind OpenClaw and the frequency of pairing operations in your environment.
Frequently asked questions
Can an attacker exploit this without intercepting a bootstrap token?
No. The vulnerability requires the attacker to obtain or intercept an actual bootstrap token and then replay it. Without a valid token to begin with, the attack cannot proceed. This requirement limits exploitation to scenarios where attackers can monitor network traffic during pairing or convince a user to click a malicious link.
Does this vulnerability affect existing paired devices, or only new pairings?
The vulnerability applies to the bootstrap pairing process itself, so it primarily affects new device pairings. However, if an attacker successfully escalates scope during pairing, the resulting paired device retains the elevated permissions, potentially affecting long-term security of the system.
What is the difference between the original token scope and the replayed scope?
The bootstrap token is issued with specific permissions for a limited pairing operation. An attacker can replay the same token but request additional scopes—for example, administrative access instead of read-only access. The vulnerable code does not properly validate that the new scope matches the original authorization, allowing this escalation.
If we are on version 2026.5.11, are we definitely affected?
Yes. Any version before 2026.5.12 is affected according to the vendor advisory. You should plan an upgrade to 2026.5.12 or later as soon as your change management process allows.
This analysis is based on the CVE-2026-53862 official description and CVSS metrics published as of 2026-06-17. Organizations should verify patch availability and compatibility with their OpenClaw deployment by consulting the vendor's security advisory. No exploit code or proof-of-concept is provided. This assessment does not constitute legal or compliance advice; security teams should apply internal risk frameworks appropriate to their environment before deciding on patching priority. Source: NVD (public-domain), retrieved 2026-07-24. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-53847MEDIUMOpenClaw Privilege Escalation via Insufficient Scope Validation
- CVE-2026-53814HIGHOpenClaw Privilege Escalation via Hook-Triggered Agent Scope Mismatch
- CVE-2026-10070MEDIUMmacrozheng mall Admin Authorization Bypass in /admin/update/
- CVE-2026-10152MEDIUMImproper Access Control in TaleLin lin-cms-spring-boot Book Endpoint
- CVE-2026-10215MEDIUMDolibarr Leave Request API Authorization Bypass
- CVE-2026-10217MEDIUMGoClaw Privilege Escalation in RoleAdmin Gateway (CVSS 6.3)
- CVE-2026-10218MEDIUMGoClaw Improper Authorization Vulnerability (CVSS 5.4)
- CVE-2026-10255MEDIUMPharmacy Sales System Authentication Bypass – SourceCodester 1.0