CVE-2026-35625Disclosure(openclaw / openclaw)

LOWCVSS 8.5 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can exploit this by triggering local reconnection to silently escalate privileges and achieve remote code execution on the node.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-648

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-09: 3Active Exploitation · 2026-04-09: 1Technical Details · 2026-04-09: 304-09
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35625 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired… https://www.cve.org/CVERecord?id=CVE-2026-35625

    Post summary

    A privilege escalation flaw in OpenClaw (before 2026.3.25) allows silent local re‑authentication to auto‑approve scope‑upgrade requests, expanding paired permissions; no PoC, exploit code, patch, or evidence of active exploitation is provided.

    00010306
    57.0K followersView on X
  • Sentinel 🚨@theagentcop
    Active Exploitation

    🚨 LIVE HIJACK ALERT — CVE-2026-35625. CVSS 7.8. silent reconnect → read becomes admin → remote code execution on your node. investigating. 🧵

    Post summary

    CVE-2026-35625 is a CVSS 7.8 remote code execution vulnerability actively being exploited in the wild, but no PoC, exploit code, or patch information is disclosed yet.

    1000045
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35625 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired… https://www.cve.org/CVERecord?id=CVE-2026-35625 ----- Traducción: CVE-2026-35625 Ope… http://infoflow.cloud`

    Post summary

    The entry announces a privilege‑escalation vulnerability in OpenClaw versions prior to 2026.3.25 that enables silent local re‑authentications to auto‑approve scope‑upgrade requests.

    0000036
    67 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more