CVE-2026-41352

8.8

OpenClaw · OpenClaw

OpenClaw before 2026.3.31 allows authenticated attackers with device-pairing credentials to bypass node scope gate authentication and execute arbitrary commands on the host system.

Executive summary

A remote code execution vulnerability in OpenClaw allows attackers with valid device pairing credentials to execute unauthorized commands on the host system.

Vulnerability

This is a missing authorization flaw (CWE-862) occurring within the node scope gate authentication mechanism. The vulnerability permits an attacker who already possesses device-pairing credentials to bypass security checks and execute arbitrary commands on the underlying host system.

Business impact

The ability to execute arbitrary code on a host system represents a critical security risk, potentially leading to a full system compromise, unauthorized data access, and lateral movement within the network. With a CVSS score of 8.8, this vulnerability is classified as High severity and necessitates immediate attention to prevent operational disruption or the theft of sensitive proprietary data.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.31 or later to implement the necessary authorization checks.

Proactive Monitoring: Review system and application access logs for unusual command execution patterns or unauthorized attempts to access the node scope gate interface.

Compensating Controls: Implement strict network segmentation to limit the reach of devices with pairing credentials, and ensure that access to the management interfaces is restricted to authorized personnel only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution, organizations utilizing OpenClaw must prioritize updating to version 2026.3.31 immediately. Failure to patch allows authenticated attackers to escalate their privileges into full system control, posing an unacceptable risk to the integrity and availability of the host environment.

More OpenClaw CVEs

Sources

Originally found and disclosed by AntAISecurityLab, per the CVE Program record.