CVE-2026-33575
7.5OpenClaw · OpenClaw
OpenClaw versions before 2026.3.12 expose shared gateway credentials within pairing setup codes, allowing unauthorized credential reuse.
Executive summary
A critical credential exposure vulnerability in OpenClaw allows attackers to intercept and reuse shared gateway credentials, potentially leading to unauthorized system access.
Vulnerability
The software suffers from insufficient protection of credentials, where long-lived shared gateway credentials are embedded in pairing setup codes generated by the /pair endpoint and the OpenClaw qr command. This flaw is exploitable by an unauthenticated attacker who gains access to these codes via logs, chat history, or screenshots.
Business impact
The exposure of shared gateway credentials poses a significant risk to the integrity and confidentiality of the entire communication infrastructure managed by OpenClaw. With a CVSS score of 7.5, this high-severity vulnerability could allow unauthorized parties to impersonate legitimate gateways, leading to data interception or full system compromise. The potential for widespread unauthorized access necessitates immediate attention to prevent operational disruption and loss of sensitive information.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.3.12 or later to ensure shared gateway credentials are no longer embedded in pairing codes.
Proactive Monitoring: Review application logs and internal documentation repositories for the presence of leaked pairing setup codes that may have been stored historically.
Compensating Controls: Restrict access to logs and sensitive communication channels where pairing codes might be shared, and implement strict rotation policies for any gateway credentials that may have been exposed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk associated with this vulnerability is high due to the potential for persistent unauthorized access using recovered credentials. Organizations utilizing OpenClaw must prioritize the upgrade to version 2026.3.12 immediately to eliminate the exposure vector. Following the update, security teams should conduct a thorough audit of existing gateway configurations to ensure no compromised credentials remain in active use.
More OpenClaw CVEs
Sources
Originally found and disclosed by lintsinghua, Knoxar (@woreksami), per the CVE Program record.
- GitHub Security Advisory (GHSA-7h7g-x2px-94hj) Vendor advisory
- VulnCheck Advisory: OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes Third-party advisory