{"id":"CVE-2026-53817","aliases":["GHSA-chr9-m4q2-76hw"],"url":"https://o3.security/vulnerability/CVE-2026-53817","summary":"OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing","details":"### Summary\n\nIn affected LAN/shared-token Control UI deployments, a caller could spoof locality information used during Control UI pairing and obtain a durable admin-capable device token.\n\nThis issue is limited to deployments where the caller already has the network/authentication foothold needed to reach the Control UI pairing path. It is not an unauthenticated internet exposure issue.\n\n### Affected configurations\n\nThis affects configurations such as LAN-bound gateways or shared-token Control UI access where locality signals were accepted as sufficient for pairing decisions.\n\n### Impact\n\nA temporary or shared Control UI access path could be turned into a persistent admin device token. That token could remain useful after the shared gateway token was rotated, unless the paired device was removed.\n\nThe issue is a pairing/locality validation problem: locality-derived trust was stronger than it should have been.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.22`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.22` or later. For older deployments, remove unexpected paired devices and avoid exposing Control UI pairing paths on networks with untrusted clients.","published":"2026-06-11T20:09:38.043Z","modified":"2026-08-12T03:51:13.976263089Z","cvss":null,"epss":{"score":0.00309,"percentile":0.23756,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.5.22"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53817.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-chr9-m4q2-76hw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53817"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-control-ui-locality-spoofing-in-device-pairing"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.976263089Z"}}