CVE-2026-42432
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.
View on NVDAnalysis
OpenClaw is a specialized automation or assistant platform with limited adoption in the general developer community. While the privilege escalation vulnerability allows unauthorized command execution on the host, the product is not widely used enough to warrant a community-wide alert.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-863EPSS
Affects
openclaw:openclawTechnical description
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.