PT-2026-28450 · Openclaw · Openclaw
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.11
Description
A privilege escalation flaw exists in the
device.token.rotate endpoint. Callers with the operator.pairing scope can mint tokens with broader permissions because the system fails to restrict newly minted scopes to the caller's current scope set. This allows an attacker to obtain operator.admin tokens for paired devices, potentially leading to unauthorized gateway-admin access or remote code execution on connected nodes via the system.run function.Recommendations
Update to version 2026.3.11 or later.
Exploit
Fix
LPE
RCE
Improper Privilege Management
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw