OpenClaw's /pair approve Command: The Backdoor That Handed Attackers 85,000 Servers
Picture this: one command, typed in under a minute, flips a low-priv user into god-mode admin. OpenClaw CVE-2026-33579 exposed 85,000+ instances to instant takeover.
DevTools FeedApr 03, 20263 min read22 views
⚡ Key Takeaways
CVE-2026-33579 allows instant admin takeover via /pair approve—no auth needed on 85k+ instances.𝕏
Patch in 2026.3.28 adds checks, but systemic trust flaws demand full RBAC redesign.𝕏
Assume compromise if unpatched: audit devices, logs, and rotate all creds immediately.𝕏
The 60-Second TL;DR
CVE-2026-33579 allows instant admin takeover via /pair approve—no auth needed on 85k+ instances.
Patch in 2026.3.28 adds checks, but systemic trust flaws demand full RBAC redesign.
Assume compromise if unpatched: audit devices, logs, and rotate all creds immediately.