CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-32922 — OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in devic...

Sunday, March 29, 2026 at 01:17 PM UTC·Source: NIST NVD

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unaut

Analysis

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access. CVSS Score: 9.9. Published: 2026-03-29T13:17:00.573.

Indicators of Compromise (1)

CVE (1)
CVE-2026-32922
Source Attribution

Originally published by NIST NVD on Mar 29, 2026. Verified by: NIST.

Related Threats