CVE-2026-41352
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
HIGH · CVSS 8.8
EPSS 0.00536
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0