« Volver al listado

CVE-2026-53852

Estado: AnalizadaBaja (2.3)—

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53852",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-53852",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-16T18:59:03.453390Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 2.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "repo": "https://github.com/openclaw/openclaw",
          "vendor": "OpenClaw",
          "product": "OpenClaw",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2026.4.25",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2026.4.25",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/openclaw",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-16T19:17:02.510",
  "references": [
    {
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-8mg9-j9cf-54cj",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-empty-scope-device-re-pairing",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-636"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access."
    }
  ],
  "lastModified": "2026-06-17T21:02:18.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1C7E0A9-FE18-4FC0-B084-962ED0BC7EC6",
              "versionEndExcluding": "2026.4.25"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47423C4C-E76E-4143-8AB9-C7828BFAB409"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta10:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "991BD889-5FA3-4665-BA49-B8DAF1F0BE19"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta11:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2DEC581-0C75-4797-AE9B-16AE8B61CFA5"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B66A863E-509A-4B70-81D7-7CBAAE35562A"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22C31BB6-8D7E-440E-9307-85E1B5D6EFE3"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA94F68E-C254-4693-8178-2350AFF03340"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81E3D764-EC83-44F8-BBBF-ACB6009B210F"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87569369-BAA7-4E88-9370-F8C6C8548EDA"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61334610-1CDA-4AC4-A62B-4CA0E1448891"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta8:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "692249CF-9643-4B03-B180-B6F7588547DE"
            },
            {
              "criteria": "cpe:2.3:a:openclaw:openclaw:2026.4.25:beta9:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "750B5EC7-F749-4656-AEE5-D1F403F56B6B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}