PT-2026-31761 · Openclaw · Openclaw
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
OpenClaw contains a privilege escalation issue where silent local shared-auth reconnects automatically approve scope-upgrade requests, increasing paired device permissions from operator.read to operator.admin. An attacker can trigger a local reconnection to escalate privileges and potentially achieve remote code execution on the node.
Recommendations
Update to version 2026.3.25 or later.
Exploit
Fix
LPE
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw