CVSS 9.83 sources verified·1 min read
By Lyrie Threat Intelligence·6/12/2026
CRITICAL: CVE-2026-53838 (CVSS 9.8) — multiple products
CVE: CVE-2026-53838
CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: CRITICAL
Status: Critical advisory
Affected
_See vendor advisory_
Summary
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.
Verified Sources
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-83w9-h5wv-j9xm
- https://www.vulncheck.com/advisories/openclaw-node-pairing-state-mutation-via-reconnection
_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._
Lyrie Verdict
A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.
Validated sources
- [1]NVD
- [2]GitHub Advisory
- [3]MITRE