← Back to CVE List
Vulnerability Intelligence Report
OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate

CVE-2026-32922

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.

No Active Exploit Signals
CVSS Base Score
9.4
CRITICAL
EPSS Probability:0.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-266 ↗Incorrect Privilege Assignment

Affected Products & Versions

Vendor Product Affected Versions
OpenClaw OpenClaw 0 < 2026.3.11 (affected), 2026.3.11 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.540%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-03-16T21:19:31
Published2026-03-29T12:44:22
Patch Date2026-03-12
Last Updated2026-06-23T16:15:21

LINK COPIED TO CLIPBOARD