CVE-2026-32042: Openclaw
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.
Affected products
- Openclaw Openclaw: from 2026.2.22, before 2026.2.25 (fixed in 2026.2.25)
Published 2026-03-21. Last modified 2026-06-17.