alert
Apr 14, 2026
By Teun
13 CVEs Patched in April — Including a Critical Device Pairing Flaw
The April security batch fixed 13 vulnerabilities averaging CVSS 7.0, with two crossing the critical threshold. The worst: a device pairing flaw letting any token escalate to full operator access.
OpenClaw’s April security batch fixes 13 vulnerabilities, with an average CVSS score of 7.0 and two issues rated critical, according to Blink Security. The most serious flaw is CVE-2026-35639, a device pairing bug that could let a token with limited rights escalate to full operator access.
Blink said the problem was in the device.pair.approve handler, which did not verify that the requesting token actually had the device.pair scope before approving a pairing request. In practice, that means a valid but low-privilege token, including one that was meant to be read-only, could be accepted as if it were authorized to pair a device.
⚡ New to this?
This is a security alert about a bug that could let someone with a limited login token become a full operator in OpenClaw. A token is a digital credential used by software to prove identity and permissions, and operator access usually means control over files, code execution, and plugins. Non-experts should care because a flaw like this can turn a small access mistake into a full system compromise.
🦞 OpenClaw angle
Update any OpenClaw instance to 2026.4.5 or later before you do anything else. Then check whether your service is exposed to the public internet without authentication, because a patched bug still leaves you vulnerable if the front door is open. Review any automation tokens and make sure each one is scoped to the minimum permissions needed, especially for pairing, admin, and plugin-related actions.
Once an attacker reaches operator access, the impact is broad. According to the summary from Blink, operator privileges can expose workspace files, allow code execution, enable plugin installation, and give access to anything the agent can reach.
The exposure is worse on instances that are publicly reachable and do not use authentication. Blink researchers said 63% of the 135,000 publicly exposed OpenClaw instances they examined run without any authentication layer at all. On those systems, the pairing flaw can be exploited remotely without credentials.
That combination of weak access control and an exposed service is what makes the issue stand out. A token that should have been limited to a narrow task can become a path to full administrative control if the server does not check scopes correctly.
The patch is available in version 2026.4.5 and later, according to the advisory. Anyone running an earlier build should plan an immediate update, and teams should verify whether their dashboard is reachable from the public internet without a login prompt.
If the instance is exposed, the next step is to treat that as a separate security issue, not just a configuration detail. The April patch closes the pairing flaw, but the underlying access model still matters for every deployment that handles sensitive files, tools, or automation actions.