Sploitus

CVE-2026-53852

1 known exploit for CVE-2026-53852

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.

Affected products
Openclaw
Openclaw
< 2026.4.25
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (11th percentile)
Weakness
CWE-636
NVD status
Analyzed
Published
2026-06-16
CVE-2026-53852 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-53852

Proof-of-concept code and exploit modules indexed by Sploitus