Junglewise Threat Intelligence

CVE-2026-42432: OpenClaw privilege escalation via node pairing reconnect bypass

CVE-2026-42432 · Severity: high · CVSS 7.8 · Published 2026-04-28

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI-powered local assistant that runs on user systems. Previously paired nodes connecting to OpenClaw can bypass authentication and gain access to privileged commands (including code execution) without requiring re-pairing and operator approval. This allows an attacker with access to a previously-paired node to execute arbitrary commands on the system with elevated privileges.

Technical details

This is an authentication bypass and privilege escalation vulnerability (CWE-863: Incorrect Authorization, CWE-288: Authentication Bypass Using an Alternate Path) in OpenClaw's node pairing mechanism. When a node that was previously paired attempts to reconnect, the system fails to properly validate authorization scope and does not force re-pairing, allowing the node to access exec-capable commands without operator.admin approval. The vulnerability requires local access and an existing pairing relationship but can lead to arbitrary command execution on the affected system. The fix was verified and deployed in version 2026.4.8 (commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5), which implements proper DNS pinning and trusted environment proxy dispatch validation before allowing command execution on reconnect.

Affected products

  • OpenClaw openclaw <=2026.4.5

Timeline

  • 2026-04-09: disclosed: Security advisory published
  • 2026-04-08: patched: Fix released in version 2026.4.8
  • 2026-04-28: advisory: NVD publication

References

Related threats