CVE-2026-32042
8.8OpenClaw · OpenClaw
OpenClaw 2026.2.22 to 2026.2.24 contains an incorrect authorization vulnerability allowing authenticated attackers to bypass device pairing and escalate privileges to operator.admin status.
Executive summary
A critical privilege escalation vulnerability in OpenClaw allows authenticated attackers to bypass security controls and gain unauthorized administrative access.
Vulnerability
The software suffers from an incorrect authorization flaw (CWE-863) where an attacker with valid shared gateway authentication can present a self-signed unpaired device identity to self-assign elevated operator scopes before pairing approval is granted.
Business impact
Successful exploitation permits an attacker to assume the identity of an administrator, leading to full control over the affected gateway and connected systems. Given the CVSS score of 8.8, this poses a high risk of unauthorized data access, system disruption, and loss of integrity for the affected environment.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.2.25 or later immediately.
Proactive Monitoring: Review system access logs for anomalous pairing requests or unauthorized changes to account roles and permissions.
Compensating Controls: Restrict access to the shared gateway infrastructure to trusted networks and implement strict monitoring of authentication events to detect suspicious identity assertions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the potential for full administrative takeover, necessitates immediate patching. Organizations running OpenClaw should prioritize upgrading to version 2026.2.25 to prevent potential exploitation of the authorization bypass mechanism.
More OpenClaw CVEs
Sources
Originally found and disclosed by tdjackey, per the CVE Program record.
- GitHub Security Advisory (GHSA-553v-f69r-656j) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentic Third-party advisory