Back to overview

CVE-2026-53838

CRITICAL
9.8
CVSS 3.1
Description
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.

Metadata

CVE ID
CVE-2026-53838
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-10 21:19 UTC
Published
2026-06-12 21:57 UTC
Last updated
2026-06-15 21:41 UTC
Primary CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
Vendor / Product
OpenClaw / OpenClaw
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
OpenClaw OpenClaw 0 < 2026.5.27, 2026.5.27
Weakness (CWE)
CWESourceDescription
CWE-367 cna Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS scores (3)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
6.0 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
References (2)
Back to overview