CVE-2026-53852EPSS p6.0%
CVE-2026-53852CVE-2026-53852
Description
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| EPSS | 0.16% probability of exploitation · percentile 6.0% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-16 |