← Back to CVE List
Vulnerability Intelligence Report
OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

CVE-2026-33579

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

No Active Exploit Signals
CVSS Base Score
9.4
CRITICAL
EPSS Probability:0.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-863 ↗CWE-863: Incorrect Authorization

Affected Products & Versions

Vendor Product Affected Versions
OpenClaw OpenClaw 0 < 2026.3.28 (affected), 2026.3.28 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.624%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-03-23T11:00:48
Published2026-03-31T14:10:32
Patch Date2026-03-29
Last Updated2026-06-23T16:15:38

LINK COPIED TO CLIPBOARD