CVE-2026-33575

7.5

OpenClaw · OpenClaw

OpenClaw versions before 2026.3.12 expose shared gateway credentials within pairing setup codes, allowing unauthorized credential reuse.

Executive summary

A critical credential exposure vulnerability in OpenClaw allows attackers to intercept and reuse shared gateway credentials, potentially leading to unauthorized system access.

Vulnerability

The software suffers from insufficient protection of credentials, where long-lived shared gateway credentials are embedded in pairing setup codes generated by the /pair endpoint and the OpenClaw qr command. This flaw is exploitable by an unauthenticated attacker who gains access to these codes via logs, chat history, or screenshots.

Business impact

The exposure of shared gateway credentials poses a significant risk to the integrity and confidentiality of the entire communication infrastructure managed by OpenClaw. With a CVSS score of 7.5, this high-severity vulnerability could allow unauthorized parties to impersonate legitimate gateways, leading to data interception or full system compromise. The potential for widespread unauthorized access necessitates immediate attention to prevent operational disruption and loss of sensitive information.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.12 or later to ensure shared gateway credentials are no longer embedded in pairing codes.

Proactive Monitoring: Review application logs and internal documentation repositories for the presence of leaked pairing setup codes that may have been stored historically.

Compensating Controls: Restrict access to logs and sensitive communication channels where pairing codes might be shared, and implement strict rotation policies for any gateway credentials that may have been exposed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk associated with this vulnerability is high due to the potential for persistent unauthorized access using recovered credentials. Organizations utilizing OpenClaw must prioritize the upgrade to version 2026.3.12 immediately to eliminate the exposure vector. Following the update, security teams should conduct a thorough audit of existing gateway configurations to ensure no compromised credentials remain in active use.

More OpenClaw CVEs

Sources

Originally found and disclosed by lintsinghua, Knoxar (@woreksami), per the CVE Program record.