CVE-2026-33577

8.1

OpenClaw · OpenClaw

OpenClaw versions prior to 2026.3.28 contain an insufficient scope validation vulnerability in the node pairing approval path, allowing low-privilege operators to escalate privileges on paired nodes.

Executive summary

A critical authorization vulnerability in OpenClaw allows authenticated low-privilege operators to bypass scope restrictions during node pairing, potentially leading to unauthorized system control.

Vulnerability

The flaw exists in the node-pairing.ts file where insufficient scope validation occurs during the node pairing approval process. This allows an authenticated low-privilege operator to approve nodes with broader scopes than their authorization level permits.

Business impact

Successful exploitation of this vulnerability enables a low-privilege actor to gain elevated control over paired nodes, resulting in unauthorized access to sensitive operational functions. Given the CVSS score of 8.1, this flaw presents a high risk of privilege escalation that could lead to significant data exposure or operational disruption within the affected environment.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.28 or later via your package manager to address the scope validation flaw.

Proactive Monitoring: Review audit logs for unusual node pairing activities, specifically looking for pairing requests initiated or approved by accounts with limited administrative permissions.

Compensating Controls: Implement strict identity and access management policies to limit the number of users with operator-level permissions until the patch can be successfully deployed.

Exploitation status

Public Exploit Available: No (Exploit_available: false)

Analyst recommendation

This vulnerability represents a significant authorization failure that undermines the principle of least privilege within the OpenClaw platform. IT administrators should prioritize upgrading to version 2026.3.28 immediately to neutralize the risk of unauthorized privilege escalation and ensure the integrity of node pairing operations.

More OpenClaw CVEs

Sources

Originally found and disclosed by AntAISecurityLab, per the CVE Program record.