📦 Open Source

OpenClaw's Privilege Escalation Bug Lets Pairers Play Admin

OpenClaw privilege-escalation bug strikes again. A simple scope slip-up turns pairers into admins—without anyone noticing.

Illustration of OpenClaw privilege escalation exploit chain in device pairing

⚡ Key Takeaways

  • CVE-2026-33579 allows pairing users to approve admin access via scope validation failure. 𝕏
  • Patch to OpenClaw 2026.3.28 immediately; audit device pairing integrations. 𝕏
  • Echoes historical priv-esc flaws, signaling risks in rushed OSS device tools. 𝕏
Published by

DevTools Feed

Ship faster. Build smarter.

Worth sharing?

Get the best Developer Tools stories of the week in your inbox — no noise, no spam.

Originally reported by Hacker News

Stay in the loop

The week's most important stories from DevTools Feed, delivered once a week.