Executive brief
OpenClaw Gateway, a tool used for managing device connections, contains a security flaw in its device approval process. An attacker with low-level pairing permissions can approve device requests with full administrative privileges, effectively taking over the gateway. This could lead to unauthorized access to sensitive data, service disruption, or complete system compromise.
Technical details
A privilege management vulnerability (CWE-269) exists in OpenClaw Gateway's 'device.pair.approve' method. The root cause is a failure to validate that the requested scopes for a new device do not exceed the scopes held by the approving operator. An attacker with 'operator.pairing' permissions can approve a pending device request and grant it 'operator.admin' scopes. This escalation can lead to Remote Code Execution (RCE) and full system compromise. The fix, introduced in version 2026.3.22, ensures that caller scopes are threaded into the approval logic and that requested scopes exceeding the approver's set are rejected.
Affected products
- OpenClaw openclaw < 2026.3.22
Timeline
- 2026-03-24: disclosed: Initial disclosure in openclaw/openclaw repository
- 2026-03-26: advisory: GitHub Advisory published
- 2026-03-22: patched: Fix released in version 2026.3.22