CRITICAL🇵🇱 Wersja polska

CVE-2026-41386

CVSS 9.1v4.0pub. 2026-04-28upd. 2026-05-01

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.

🤖 AI Analysis
How it works

During the device first-use pairing procedure, bootstrap configuration codes are not bound to specific device roles or permission scopes. The lack of this binding means that an attacker who can participate in the pairing process may use bootstrap codes in a manner unintended by the manufacturer. As a result, it is possible to obtain higher privileges than those that should be granted to a given role or device.

Impact

An attacker can escalate their privileges beyond the intended role level and scope (privilege escalation), gaining unauthorized access to OpenClaw system functions or resources restricted to privileged users or roles.

Mitigation & patch

OpenClaw should be updated to version 2026.3.22 or later, in which bootstrap codes are properly bound to device roles and permission scopes during pairing. Patch details are available in the manufacturer's references and in commit a600c72ed7d0045a27f58bf031d2b36ecb0141c9 in the GitHub repository.

Who is affected

OpenClaw in all versions before 2026.3.22

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openclaw

    APP
    Openclaw
    < 2026.3.22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-43585CRITICAL9.2PL ✓same product

OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef

CVE-2026-43578CRITICAL9.1PL ✓same product

OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat

CVE-2026-43575CRITICAL9.2PL ✓same product

OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC

CVE-2026-43581CRITICAL9.0PL ✓same product

OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox

CVE-2026-44109CRITICAL9.2PL ✓same product

OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE