CVE-2026-41352
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Apr 23, 2026
Vendor
unknown
Description
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.