PT-2026-31761 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-04-09
·
Updated
2026-04-09
·
CVE-2026-35625
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
OpenClaw contains a privilege escalation issue where silent local shared-auth reconnects automatically approve scope-upgrade requests, increasing paired device permissions from operator.read to operator.admin. An attacker can trigger a local reconnection to escalate privileges and potentially achieve remote code execution on the node.
Recommendations
Update to version 2026.3.25 or later.
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw