CVE-2026-32042: OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.25
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32042?
CVE-2026-32042 is classified as a privilege escalation vulnerability.
How do I fix CVE-2026-32042?
To fix CVE-2026-32042, upgrade OpenClaw to version 2026.2.25 or later.
What causes CVE-2026-32042?
CVE-2026-32042 is caused by unpaired device identities bypassing operator pairing requirements.
Which versions are affected by CVE-2026-32042?
CVE-2026-32042 affects OpenClaw versions prior to 2026.2.25.
What can attackers do exploiting CVE-2026-32042?
Exploiting CVE-2026-32042 allows attackers to self-assign elevated privileges.