CVE-2026-35639Disclosure(openclaw / openclaw)

MEDIUMCVSS 8.7 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attackers can exploit insufficient scope validation to escalate privileges to operator.admin and achieve remote code execution on the Node infrastructure.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-648

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 2Mentions · 2026-04-12: 1Active Exploitation · 2026-04-10: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 2Technical Details · 2026-04-12: 104-0904-1004-12
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure2Patch1
2026-04-102
Active Exploitation1Disclosure1
2026-04-121
Disclosure1
Full discourse6 posts
  • Sentinel 🚨@theagentcop
    Active Exploitation

    🚨 LIVE HIJACK ALERT — CVE-2026-35639. CVSS 8.8. attackers approve their own device pairing requests with escalated scopes, walk straight to operator.admin, execute code on your node infrastructure. investigating. 🧵

    Post summary

    The post alerts that CVE-2026-35639 is actively exploited, enabling attackers to elevate privileges via device pairing and execute arbitrary code on node infrastructure.

    1000045
    6 followersView on X
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 TODAY'S TOP 3 AGENT THREATS — 1. ghost session privilege takeover (CVE-2026-35638) unauthenticated sessions self-declare admin scopes without device verification and your control UI just believes them 2. scope laundering via pairing approval (CVE-2026-35639) low-privilege operators approve device pairings with broader scopes than they hold, granting themselves capabilities they were never authorized for 3. reconnect-to-admin bypass (CVE-2026-35663) non-admin operators request admin scopes during backend reconnect and bypass pairing requirements entirely is your agent on the list? → http://agentcop.live #AgentSecurity #CVE

    Post summary

    A tweet announces three newly disclosed CVEs affecting agent software, providing brief technical descriptions of each vulnerability but not discussing exploits, patches, or active attacks.

    0000037
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35639 Privilege Escalation in OpenClaw Before 2026.3.22 Device Pairing Approval https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35639

    Post summary

    A vulnerability (CVE-2026-35639) has been disclosed as a privilege escalation issue in OpenClaw devices before version 2026.3.22, with no PoC, patch, or exploitation claims mentioned.

    0000060
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35639: HIGH] Vulnerability alert: OpenClaw (pre-2026.3.22) has a privilege escalation flaw in device.pair.approve. Exploitation may lead to operator.admin rights & remote code execution. Update now!#cve,CVE-2026-35639,#cybersecurity https://cvefind.com/CVE-2026-35639

    Post summary

    The post alerts on a privilege escalation flaw in OpenClaw that could enable remote code execution, urging users to immediately apply a patch.

    0000048
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35639 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending … https://www.cve.org/CVERecord?id=CVE-2026-35639 ----- Traducción: CVE-2026-35639 Ope… http://infoflow.cloud`

    Post summary

    The post announces a privilege‑escalation vulnerability (CVE‑2026‑35639) in OpenClaw, providing a brief technical description and a link to the CVE record.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35639 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending … https://www.cve.org/CVERecord?id=CVE-2026-35639

    Post summary

    The entry describes a privilege escalation vulnerability in OpenClaw's device.pair.approve method, providing technical details but lacking PoC, exploit code, or mitigation information.

    00000176
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more