CVE-2026-32042: Openclaw

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.

Affected products

  • Openclaw Openclaw: from 2026.2.22, before 2026.2.25 (fixed in 2026.2.25)

Published 2026-03-21. Last modified 2026-06-17.