OpenClaw privilege escalation vulnerability
8.8 relevance
Score Breakdown
technical depth 9
novelty 8
actionability 9
community 9
strategic 9
personal 9
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
OpenClaw privilege escalation is a critical vulnerability in an AI-adjacent tool requiring immediate patching.
Summary
OpenClaw before version 2026.3.28 has a high-severity privilege escalation vulnerability (CVE-2026-33579, CVSS 3.1: 8.1) in the /pair approve command. The flaw in extensions/device-pair/index.ts and src/infra/device-pairing.ts fails to forward caller scopes, allowing pairing-privileged users to approve admin-access requests. This incorrect authorization (CWE-863) enables attackers to escalate privileges via missing scope validation.