Junglewise Threat Intelligence

CVE-2026-35625: OpenClaw privilege escalation in gateway shared-auth reconnect

CVE-2026-35625 · Severity: medium · CVSS 4 · Published 2026-03-27

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a device authentication and authorization gateway. A flaw in its local reconnection mechanism allows paired devices to silently escalate their privileges from read-only to admin level without explicit user approval, potentially enabling remote code execution on connected nodes.

Technical details

OpenClaw's gateway authentication system contains an incorrect authorization check (CWE-863) in the shared-auth reconnection logic. When a paired device reconnects using cached local authentication credentials, the system silently auto-approves scope-upgrade requests, allowing privilege escalation from operator.read to operator.admin scope without requiring explicit pairing re-approval. Attack requires local network adjacency and prior device pairing (operator.read privilege already held). An authenticated device can exploit this to reach node RCE. The vulnerability was patched in commit 81ebc7e by blocking silent scope-upgrade reconnects and requiring explicit approval for any scope widening.

Affected products

  • OpenClaw openclaw <= 2026.3.24

Timeline

  • 2026-03-27: disclosed
  • 2026-03-25: patched: Fix commit 81ebc7e0344fd19c85778e883bad45e2da972229; version 2026.3.25

References

Related threats