CVE-2026-32922: OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate
Published Mar 29, 2026
·Updated
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.
Affected Software
2 affected components
OpenClaw OpenClaw<2026.3.11
OpenClaw Openclaw Node.js<2026.3.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.11
Event History
Mar 29, 2026
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is impacted by CVE-2026-32922?
Users of OpenClaw prior to version 2026.3.11 are impacted by CVE-2026-32922.