CVE-2026-33579Disclosure(openclaw / openclaw)

MEDIUMCVSS 9.4 · CRITICAL

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 45 mentions across 12 observed days

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 36 signals
  • Disclosure: 18 classified signals
  • General: 8 classified signals
  • Peaked 9d ago at 15 mentions (2026-04-04); latest day: 1
  • 45 total mentions across 12 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline45 mentions / 12d
0481115Mentions · 2026-03-31: 3Mentions · 2026-04-03: 2Mentions · 2026-04-04: 15Mentions · 2026-04-05: 11Mentions · 2026-04-06: 3Mentions · 2026-04-07: 4Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-05-16: 1Mentions · 2026-07-16: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-07: 1Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-05: 3Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-04: 7Patch / Workaround · 2026-04-05: 8Patch / Workaround · 2026-04-06: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-03: 2Technical Details · 2026-04-04: 12Technical Details · 2026-04-05: 8Technical Details · 2026-04-06: 3Technical Details · 2026-04-07: 3Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-16: 103-3104-0304-0404-0504-0604-0704-0804-0904-1504-1705-1607-16
Signal classification5 categories
Disclosure
1840.0%
Patch
1226.7%
General
817.8%
Active Exploitation
613.3%
False Positive
12.2%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-03-313
Disclosure3
2026-04-032
Disclosure1Patch1
2026-04-0415
Active Exploitation1Disclosure5General4Patch5
2026-04-0511
Active Exploitation3Disclosure2False Positive1General1Patch4
2026-04-063
Disclosure2Patch1
2026-04-074
Disclosure4
2026-04-082
Disclosure1General1
2026-04-091
Patch1
2026-04-151
Active Exploitation1
2026-04-171
Active Exploitation1
2026-05-161
General1
2026-07-161
General1
Full discourse20 posts
  • alan ⚡💵@0xalank
    Patch

    Another OpenClaw attack vector dropped 😳 CVE-2026-33579 lets anyone with pairing access escalate to full admin on exposed instances @Entropic_AI was designed to prevent against these exact types of attacks Local sandbox, gateway bound to localhost only, bridge network isolation The attack vector doesn't exist at all since your OpenClaw agent is running locally 👍

    Post summary

    The post claims that CVE‑2026‑33579 is mitigated by OpenClaw’s local‑only agent design, effectively asserting the attack vector does not exist in practice.

    1072274845
    45.8K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚨 CVE-2026-33579: OpenClaw privilege escalation in `/pair approve`. An attacker with pairing access can approve admin-level requests and take over the instance. Fixed in OpenClaw 2026.3.28 — update now. https://nvd.nist.gov/vuln/detail/CVE-2026-33579

    Post summary

    A new OpenClaw privilege‑elevation flaw (CVE‑2026‑33579) lets attackers with pairing access promote themselves to admin and take over the instance; it is fixed in version 2026.3.28 and users should update immediately.

    0110170150
    1.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🚨 تنبيه : توجد ثغرة في OpenClaw تسمح للمستخدمين بصلاحيات بسيطة أنهم يحصلون على Admin. رقم الثغرة: CVE-2026-33579 📷 ⚠️ حدث الآن https://t.co/uk5DbEGCNU

    Post summary

    The tweet alerts that CVE-2026-33579 in OpenClaw lets users with limited permissions elevate to admin, but it provides no exploitation code, patches, or evidence of active attacks.

    0101272.4K
    49.2K followersView on X
  • Tareq Alhazzaa | طارق الهزاع@TareqALhazzaa
    Patch

    ثغرة CVE-2026-33579 في نظام OpenClaw، وتم إصلاحها في الإصدار 2026.3.28. https://blink.new/blog/cve-2026-33579-openclaw-privilege-escalation-2026 https://t.co/uZYDrMxaXJ

    Post summary

    The post announces that CVE-2026-33579, a privilege escalation issue in OpenClaw, has been patched in version 2026.3.28, with no active exploitation or PoC cited.

    020101533
    7.9K followersView on X
  • andy@1a1n1d1y
    Active Exploitation

    show out to all the openclaw users hacked by CVE-2026-33579 pwned if you aren't on hermes you should probably switch, idk, today? maybe a week ago if you don't like getting hacked

    Post summary

    The post claims that users of OpenClaw were compromised by CVE‑2026‑33579 and recommends switching to Hermes to avoid being hacked.

    100102914
    7.3K followersView on X
  • GeekNews@GeekNewsHada
    Disclosure

    OpenClaw 권한 상승 취약점 (CVE-2026-33579) - OpenClaw 2026․3․28 이전 버전에서 비관리자 사용자가 관리자 권한 요청을 승인할 수 있는 권한 상승 취약점이 발견됨 - `/pair approve` 명령에서 scope 전달 누락으로 인해 승인 검증이 제대로 수행되지 않아 잘못된 권… https://news.hada.io/topic?id=28201

    Post summary

    A privilege‑escalation flaw (CVE-2026-33579) in OpenClaw 2026.3.28 and earlier lets non‑admin users approve admin requests because the `/pair approve` command omits scope validation.

    111141.9K
    25.0K followersView on X
  • Winson Tang@winsontang
    General

    🚨 Security alert! The OpenClaw privilege escalation vulnerability (CVE-2026-33579) could allow unauthorized access. Stay informed and ensure your systems are protected. Don't wait for a breach—act now! #CyberSecurity #Vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-33579

    Post summary

    The post warns about a privilege escalation issue (CVE-2026-33579) and urges precaution, but includes no PoC, exploit, or patch details.

    01021199
    9.0K followersView on X
  • Dr Vincent Sativa@PhantomByteAI
    Patch

    🚨CRITICAL VULNERABILITY🚨 A serious vulnerability (CVE-2026-33579) has been discovered in OpenClaw, allowing attackers with basic privileges to gain full admin access. With 347k GitHub stars, the attack surface is massive. Patch NOW and assume compromise. https://t.co/C2MTasdAlj

    Post summary

    The tweet alerts to a critical CVE in OpenClaw that permits privilege escalation, stresses patching immediately, but offers no evidence of active exploitation or proof‑of‑concept.

    10011118
    19.3K followersView on X
  • Hexon@hexonbot
    Disclosure

    OpenClaw CVE-2026-33579 exposes 135,000+ AI agents to privilege escalation. 63% run zero auth - discover the attack chain and defenses. https://www.hexon.bot/blog/openclaw-cve-2026-33579-privilege-escalation-exposed-agents #AIsecurity #Cybersecurity #OpenClaw

    Post summary

    The post announces that CVE‑2026‑33579 allows privilege escalation in over 135,000 AI agents, with 63% operating with zero authentication, and outlines the attack chain and potential defenses.

    20010122
    404 followersView on X
  • Brandon ✌︎('ω')✌︎@BrandonMathis
    Disclosure

    🦞 is constantly getting pwned but people claim the risk is worth the reward 🤔 OpenClaw CVE-2026-33579, is rated from 8.1 to 9.8 out of a possible 10 depending on the metric used. It allows anyone with pairing privileges (the lowest-level permission) to gain administrative status. With that, the attacker has control of whatever resources the OpenClaw instance does. https://arstechnica.com/security/2026/04/heres-why-its-prudent-for-openclaw-users-to-assume-compromise/

    Post summary

    The snippet announces OpenClaw CVE‑2026‑33579, detailing its severity range and how pairing privileges allow privilege escalation, but it does not provide a PoC, exploit code, or patch information.

    1001070
    599 followersView on X
  • ALMA letairun@ALMA_letairun
    General

    Two HN stories about OpenClaw today. #1: Anthropic blocks Claude Code subscriptions. Too much access (cheap tokens for agents). #10: CVE-2026-33579 privilege escalation. Too much access (missing scope check). Same platform. Opposite gaps. http://letairun.com/creations/the-two-gaps

    Post summary

    The post cites CVE‑2026‑33579 as a privilege‑escalation flaw caused by a missing scope check, but provides no evidence of active exploitation, PoC, or patch information.

    00110270
    10 followersView on X
  • ThePixelsAndPulse@thepixelspulse
    Patch

    OpenClaw's latest vulnerability, CVE-2026-33579, lets attackers get admin access via an incomplete fix. Over 135,000 instances are exposed, 63% unauthenticated. Patch now! https://thepixelspulse.com/posts/openclaw-privilege-escalation-cve-2026-33579/ https://t.co/vuDstj4Qrx

    Post summary

    A newly disclosed CVE‑2026‑33579 in OpenClaw allows attackers to gain admin rights via an incomplete fix, affecting over 135,000 instances; users are urged to apply the available patch promptly.

    1010077
    11 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2026-33579 in OpenClaw allows privilege escalation via the /pair approve workflow, enabling users with pairing scope to grant themselves admin access. The flaw stems from missing scope validation, allowing full instance takeover on vulnerable deployments, particularly those without authentication. https://blink.new/blog/cve-2026-33579-openclaw-privilege-escalation-2026

    Post summary

    A blog post discloses a privilege‑escalation flaw in OpenClaw’s pairing workflow that lets users with pairing scope become admins, especially on instances lacking authentication, but no exploit code or active use is mentioned.

    00002126
    2.1K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    General

    CVE-2026-33579、CVSS 9.8。OpenClawに権限昇格脆弱性。 ペアリング権限から管理者制御を奪取可能。 ↓詳細はリプライで #脆弱性 https://t.co/gVUukwAmQR

    Post summary

    The tweet announces CVE‑2026‑33579 as a high‑severity privilege escalation flaw in OpenClaw, but offers no proof of exploitation, code, or patch information.

    1000073
    272 followersView on X
  • The New Claw Times@newclawtimes
    General

    CVE-2026-33579 scores 9.8 on CVSS. 63% of internet-exposed OpenClaw instances have no authentication at all. Ars Technica's Dan Goodin: assume compromise.

    Post summary

    The message shares a high CVSS score for CVE‑2026‑33579 and notes widespread lack of authentication in OpenClaw, but offers no PoC, exploit, patch, or active exploitation evidence.

    1000033
    34 followersView on X
  • AveNews@avenewsam
    Disclosure

    A critical bug (CVE-2026-33579) allowed silent administrative access to OpenClaw instances. Security scans found 63% of exposed instances had no authentication enabled. https://www.avenews.am/en/posts/openclaw-ai-tool-hit-by-critical-security-flaw

    Post summary

    The analysis reveals that CVE‑2026‑33579 allows silent administrative access to OpenClaw instances, with a significant portion of exposed systems lacking authentication, but no PoC, exploit, or patch information is provided.

    0001048
    9 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenClaw (npm), Privilege Escalation, #CVE-2026-33579 (Critical) https://dailycve.com/openclaw-npm-privilege-escalation-cve-2026-33579-critical/

    Post summary

    A new critical privilege‑escalation vulnerability in the OpenClaw npm package (CVE‑2026‑33579) has been disclosed via a short article link.

    0001034
    178 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Critical vulnerability (CVE-2026-33579) in `OpenClaw` allows device pairing escalation via the `/pair approve` command due to scope subsetting issues. Review access controls. #OpenClaw #Vulnerability #Security https://www.pulsepatch.io/posts/cve-2026-33579-openclaw-device-pairing-escalation

    Post summary

    The post announces a critical vulnerability (CVE-2026-33579) in OpenClaw, describing an escalation of device pairing via the `/pair approve` command due to scope subsetting issues, but it does not provide PoC, exploit code, or patch details.

    0001038
    11 followersView on X
  • vincent@vincentshaj
    Disclosure

    OpenClaw 再曝严重安全隐患,2026 年 4 月披露并修复的高危漏洞 CVE-2026-33579 可在没有额外交互的情况下,将拥有最低“operator.pairing”权限的设备悄然升级为“operator.admin”,从而完全接管 OpenClaw 实例并访问其连接的所有数据源与凭据。详见:https://vincent-blog.top/posts/openclaw-privilege-escalation/ https://t.co/kc0jJXqamP

    Post summary

    The post announces a high‑severity CVE‑2026‑33579 that enables privilege escalation on OpenClaw by silently upgrading devices from 'operator.pairing' to 'operator.admin', and provides a link for more details.

    0001059
    13 followersView on X
  • Singularity@promptprofitsai
    Disclosure

    🚨 Critical OpenClaw security vulnerabilities exposed A severe CVE-2026-33579 flaw (8.1-9.8 severity) lets attackers escalate from basic pairing privileges to full admin access. Security experts now recommend OpenClaw users assume potential compromise and update immediately. https://arstechnica.com/security/2026/04/heres-why-its-prudent-for-openclaw-users-to-assume-compromise/ #AI #ArtificialIntelligence #AINews #Tech

    Post summary

    A new critical vulnerability, CVE-2026-33579, has been disclosed in OpenClaw, allowing privilege escalation; users are urged to update immediately.

    1000076
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more