#VU125223 Improper access control in OpenClaw - CVE-2026-33577
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in node pairing approval path in src/infra/node-pairing.ts and src/gateway/server-methods/nodes.ts when approving pending node requests with requested scopes. A remote user can approve a pending node request for broader scopes to escalate privileges.
The issue occurs because the approving caller was not consistently required to already hold every scope requested by the node.