LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33579

CVE-2026-33579 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 31, 2026

OpenClaw - Privilege Escalation

Published: March 31, 2026Updated: March 31, 2026Remote Exploitable

Overview

OpenClaw < 2026.3.28 contains a privilege escalation vulnerability caused by missing scope validation in /pair approve command path, letting callers with pairing privileges escalate to admin access, exploit requires pairing privileges.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers with pairing privileges can escalate to admin access, compromising system control and security.

Mitigation

Update to version 2026.3.28 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 31, 2026

šŸ”“ CVE-2026-33579 - Critical (9.8) OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve p... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33579/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 31, 2026

šŸ”“ CVE-2026-33579 - Critical (9.8) OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve p... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33579/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33579
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-863

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days