<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:13:29 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-53843 — OpenClaw: Pairing-scoped device session could restore revoked node token authority</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53843</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.&lt;/p&gt;
&lt;p&gt;This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.&lt;/p&gt;
&lt;p&gt;The impact is limited to devices that already had a legitimate pairing/session foothold.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.26`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.26` or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.&lt;/p&gt;
&lt;p&gt;This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.&lt;/p&gt;
&lt;p&gt;The impact is limited to devices that already had a legitimate pairing/session foothold.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.26`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.26` or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53843</guid>
    </item>
    <item>
      <title>EUVD-2026-328348</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328348</link>
      <description>EUVD-2026-328348</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328348</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53843</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53843</link>
      <description>&lt;p&gt;OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53843</guid>
    </item>
    <item>
      <title>GHSA-q99w-vh6v-q3v7 — OpenClaw: Pairing-scoped device session could restore revoked node token authority</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q99w-vh6v-q3v7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.&lt;/p&gt;
&lt;p&gt;This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.&lt;/p&gt;
&lt;p&gt;The impact is limited to devices that already had a legitimate pairing/session foothold.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.26`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.26` or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.&lt;/p&gt;
&lt;p&gt;This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.&lt;/p&gt;
&lt;p&gt;The impact is limited to devices that already had a legitimate pairing/session foothold.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.26`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.26` or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q99w-vh6v-q3v7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1738 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</guid>
    </item>
  </channel>
</rss>
