HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53817Published Modified CNA VulnCheck

CVE-2026-53817: OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
2026.5.22
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a locality spoofing vulnerability in OpenClaw's Control UI device pairing flow, affecting all versions before 2026.5.22. An authenticated attacker with network access can send forged locality information during the pairing handshake, bypassing the trust validation that is supposed to limit shared access. Successful exploitation lets the attacker convert a temporary shared-access grant into a durable admin-capable device token that persists even after token rotation. A patched-image rebuild at version 2026.5.22 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection capability for CVE-2026-53817 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of publication. Coverage extends to custom-built images that bundle OpenClaw, not just official upstream images.

Available
Triage

HarborGuard scores this CVE at CVSS v4.0 8.7 (HIGH) and can weight that score against each customer environment's compliance policy to determine urgency. Findings are routed to the appropriate team inbox within the customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.22 becomes available through HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard will trigger a rebuild, run regression tests, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the OpenClaw Control UI pairing endpoint over the network; there is no local or physical access requirement.

  • AuthenticationRequired

    A low-privilege account is sufficient; the attacker needs any valid credential to initiate the pairing flow and inject spoofed locality data.

  • Victim interactionNot required

    No user action is needed; the attacker drives the exploit entirely through the pairing API without involving another user.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special timing, race conditions, or environmental preconditions.

Blast Radius

  • The attacker obtains a durable admin-capable device token, giving persistent administrative access to the paired device.
  • Because the token survives rotation, standard token-invalidation responses do not evict the attacker from the session.
  • With admin-level token access, the attacker can read stored configuration, credentials, and any data accessible to an admin session on the device.
  • The attacker can modify device configuration and access controls, potentially establishing a persistent foothold that outlasts incident-response actions.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-53817 is active across all connected registries and pipelines, matching against both upstream OpenClaw images and any custom images that bundle the library. For environments running an affected version (any OpenClaw release before 2026.5.22), a patched-image rebuild at 2026.5.22 is available. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; for HIGH-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy does not permit auto-remediation, the finding is surfaced in the triage queue with the CVSS v4.0 8.7 HIGH score and routing applied per the customer's configured ownership rules. As an interim compensating control, restricting network access to the Control UI pairing endpoint via network policy reduces the exposed attack surface until the patched image is deployed.

See how HarborGuard automates this

Fix available

2026.5.22
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.22 (from 0)
    Fixed in 2026.5.22
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N