CVE-2026-33579: OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33579?
CVE-2026-33579 is classified as a privilege escalation vulnerability.
How do I fix CVE-2026-33579?
To fix CVE-2026-33579, update OpenClaw to version 2026.3.28 or later.
What systems are affected by CVE-2026-33579?
CVE-2026-33579 affects OpenClaw versions prior to 2026.3.28.
What is the impact of CVE-2026-33579?
The impact of CVE-2026-33579 allows unauthorized users to escalate their privileges through device pair approval.
Is there a workaround for CVE-2026-33579?
There are currently no known workarounds for CVE-2026-33579; the recommended mitigation is to perform the version update.