{"id":"CVE-2026-33579","title":"OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check","summary":"OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"openclaw","product":"openclaw","affected":["openclaw < 2026.3.28"],"patched":["openclaw 2026.3.28"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33579","references":[{"url":"https://github.com/openclaw/openclaw/commit/e403decb6e20091b5402780a7ccd2085f98aa3cd","label":"disclosure@vulncheck.com"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-hc5h-pmr3-3497","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-missing-caller-scope-validation-in-device-pair-approval","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.00828,"epssPercentile":0.55942,"ingestedAt":"2026-07-24T21:39:13.168Z","exploits":{"github":1,"githubRepos":["https://github.com/atalovesyou/openclaw-security-checker"],"checkedAt":"2026-09-23T07:13:59.306Z"},"exploitAvailable":true,"slug":"CVE-2026-33579","body":"## Overview\n\nOpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.\n\n## Affected\n\n- `openclaw < 2026.3.28`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openclaw 2026.3.28`","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":54.5,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5109,"id":"CVE-2026-33579","ts":1788887248629,"field":"exploit_available","old":"false","new":"true"},{"seq":3992,"id":"CVE-2026-33579","ts":1788886364289,"field":"exploit_available","old":"true","new":"false"},{"seq":2807,"id":"CVE-2026-33579","ts":1788883031000,"field":"exploit_available","old":"false","new":"true"},{"seq":1836,"id":"CVE-2026-33579","ts":1788882433917,"field":"exploit_available","old":"true","new":"false"},{"seq":934,"id":"CVE-2026-33579","ts":1788881867644,"field":"exploit_available","old":"false","new":"true"}]}