CVE-2026-32042Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-21); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-21: 4Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 103-2103-22
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-214
Disclosure3General1
2026-03-221
Patch1
Full discourse5 posts
  • Agentic Yield@AgenticYield
    Patch

    CVE-2026-32042 (CVSS 8.8, HIGH): OpenClaw versions 2026.2.22 through 2026.2.24 have a privilege escalation flaw — unpaired device identities can bypass operator pairing. Update to 2026.2.25+. https://www.thehackerwire.com/openclaw-privilege-escalation-via-unpaired-device-identity/

    Post summary

    CVE-2026-32042 is a high‑severity privilege escalation flaw affecting OpenClaw 2026.2.22‑24, mitigated by upgrading to 2026.2.25+, with detailed severity and patch information highlighted.

    0000031
    12 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32042 - High OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevate... https://www.thehackerwire.com/vulnerability/CVE-2026-32042/ https://t.co/svBVxpoPwG

    Post summary

    The tweet announces the high‑severity CVE‑2026‑32042, a privilege escalation bug in specific OpenClaw versions, and links to an external article for details.

    0000051
    142 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32042 OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirement… https://www.cve.org/CVERecord?id=CVE-2026-32042

    Post summary

    The post discloses CVE-2026-32042 as a privilege escalation flaw in OpenClaw versions older than 2026.2.25 that lets unpaired devices bypass the operator pairing requirement.

    0000091
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-32042 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32042-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32042 #openclaw #

    Post summary

    The statement appears to be a basic CVE alert announcing CVE‑2026‑32042 with a link for further details, without providing additional information such as PoC, exploit code, or technical specifics.

    0000081
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32042: HIGH] Critical privilege escalation vulnerability discovered in OpenClaw versions 2026.2.22 to 2026.2.25. Attackers can bypass pairing requirements to gain elevated operator scopes. #cyberse...#cve,CVE-2026-32042,#cybersecurity https://cvefind.com/CVE-2026-32042

    Post summary

    The post announces a new high‑severity privilege escalation vulnerability (CVE‑2026‑32042) in OpenClaw, detailing how attackers can bypass pairing to gain elevated operator scopes, with no PoC, exploit, or patch information provided.

    0000066
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more