PT-2026-29259 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-03-31

·

Updated

2026-04-16

·

CVE-2026-33579

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenClaw versions prior to 2026.3.28
Description: A privilege escalation vulnerability exists in the /pair approve command path due to missing scope validation. A user with pairing privileges, but without admin privileges, can approve pending device requests for broader scopes, including admin access. This is due to the failure to forward caller scopes into the core approval check in extensions/device-pair/index.ts and src/infra/device-pairing.ts. Reports indicate that approximately 63% of internet-exposed OpenClaw instances were vulnerable due to a lack of authentication. The vulnerability allows an attacker to gain full administrative control over an instance.
Recommendations: Upgrade to version 2026.3.28 or later.

Fix

LPE

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33579
GHSA-F275-5H5C-5WG5
GHSA-HC5H-PMR3-3497

Affected Products

Openclaw