UNKNOWNCVE-2026-33579

OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

Platform

other

Component

openclaw

Fixed in

2026.3.28

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

How to fix

Actualice OpenClaw a la versión 2026.3.28 o posterior. Esta versión corrige la vulnerabilidad de escalada de privilegios al validar correctamente los alcances del llamador durante la aprobación de dispositivos.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free