OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attackers can exploit insufficient scope validation to escalate privileges to operator.admin and achieve remote code execution on the Node infrastructure.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClawReferences
https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87https://github.com/openclaw/openclaw/commit/fc2d29ea926f47c428c556e92ec981441228d2a4https://github.com/openclaw/openclaw/security/advisories/GHSA-hf68-49fm-59cqhttps://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-device-pair-approve-scope-validation