CVE-2026-32042 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requi…
High CVSS: 8.7

CVE-2026-32042

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-863
Yayın Tarihi
2026-03-21 01:17:06
Güncelleme
2026-03-23 17:10:21
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar