Removing a device or revoking its token updated stored credentials but did not disconnect already-authenticated WebSocket sessions.
A revoked device could continue using its existing live session until reconnect, extending access beyond credential removal.
src/gateway/server-methods/devices.ts, src/gateway/server.impl.ts
<= 2026.3.24>= 2026.3.282026.3.28 contains the fix.Fixed by commit 7a801cc451 (Gateway: disconnect revoked device sessions).
OpenClaw thanks @AntAISecurityLab for reporting.
2026.3.28Exploitability
AV:NAC:LAT:NPR:LUI:NVulnerable System
VC:HVI:HVA:NSubsequent System
SC:NSI:NSA:N8.6/CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N