{"id":"CVE-2026-53843","title":"OpenClaw: Pairing-scoped device session could restore revoked node token authority","summary":"OpenClaw: Pairing-scoped device session could restore revoked node token authority","severity":"high","cvss":8.8,"cwe":["CWE-284","CWE-863"],"vendor":"openclaw","product":"openclaw","ecosystem":"npm","affected":["openclaw < 2026.5.26"],"patched":["openclaw 2026.5.26"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q99w-vh6v-q3v7","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q99w-vh6v-q3v7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53843"},{"url":"https://www.vulncheck.com/advisories/openclaw-node-token-revocation-bypass-via-pairing-scoped-device-session"},{"url":"https://github.com/advisories/GHSA-q99w-vh6v-q3v7"}],"tags":["ghsa","npm"],"epss":0.00275,"epssPercentile":0.2017,"ingestedAt":"2026-06-29T14:31:47.023Z","slug":"CVE-2026-53843","body":"## Overview\n\n### Summary\n\nIn affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.\n\nThis issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.\n\n### Affected configurations\n\nThis affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.\n\n### Impact\n\nA device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.\n\nThe impact is limited to devices that already had a legitimate pairing/session foothold.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.26`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.26` or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.\n\n## Affected packages\n\n- `openclaw < 2026.5.26`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `openclaw 2026.5.26`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}