Executive brief
OpenClaw is an AI automation platform that manages device authentication tokens and permissions across operators and nodes. A critical authorization flaw allowed an attacker with limited pairing-scoped credentials to mint administrator tokens for devices, potentially gaining unauthorized admin access to gateways or—if integrated with node hosts—achieving remote code execution on the underlying infrastructure.
Technical details
The vulnerability resides in the device.token.rotate endpoint, which failed to enforce scope subsetting constraints. Specifically, the endpoint accepted caller-supplied target scopes and validated them against the target device's approved scopes, but did not verify that the newly minted token scopes were a subset of the caller's own current scope set. An attacker holding only the operator.pairing scope could exploit this to mint a new token with operator.admin scope for an already-paired device approved for admin access. This bypassed the intended privilege model and granted unauthorized gateway-admin access. In deployments where the escalated token is used against connected node hosts or companion applications exposing system.run, the attacker could further modify node execution approvals and achieve remote code execution. The vulnerability is classified as improper privilege management (CWE-269). The fix enforces caller-scope subsetting in device.token.rotate, preventing callers from minting tokens broader than their own scope set. Patched in version 2026.3.11.
Affected products
- OpenClaw openclaw <= 2026.3.8
Timeline
- 2026-03-13: disclosed
- 2026-03-13: patched: Fixed in version 2026.3.11