#VU125169 Improper privilege management in OpenClaw - CVE-2026-32987
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in bootstrap token verification in src/infra/device-bootstrap.ts when verifying bootstrap setup codes before pairing approval. A remote user can replay a valid bootstrap setup code to escalate privileges.
The issue can widen the scopes on a pending device pairing request before an approver finalizes the pairing, including escalation to operator.admin.