Description
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.
Problem types
CWE-648: Incorrect Use of Privileged APIs
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-gg9v-mgcp-v6m7 (GitHub Security Advisory (GHSA-gg9v-mgcp-v6m7))
github.com/...ommit/a600c72ed7d0045a27f58bf031d2b36ecb0141c9 (Patch Commit)
www.vulncheck.com/...ation-via-unbound-bootstrap-setup-codes (VulnCheck Advisory: OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes)