CVE-2026-42432
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without the operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.
HIGH · CVSS 7.8
EPSS 0.00027
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0