CVE-2026-33579

CRITICAL

OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

Title source: cna

Description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

Exploits (1)

nomisec NO CODE
by atalovesyou · poc
https://github.com/atalovesyou/openclaw-security-checker

Scores

CVSS v3 9.9
EPSS 0.0002
EPSS Percentile 3.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (4)
npm/openclaw 0 - 2026.3.28npm
OpenClaw/OpenClaw < 2026.3.28
openclaw/openclaw < 2026.3.28
OpenClaw/OpenClaw 2026.3.28
Published Mar 31, 2026
Tracked Since Mar 31, 2026