Improper privilege management in OpenClaw - CVE-2026-35639
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in device.pair.approve when approving a pending device request with requested operator scopes. A remote user can approve a pending device request for broader operator scopes than they hold to escalate privileges.
This can elevate a newly paired device into operator.admin, enabling access to node remote code execution capabilities.