OpenClaw, a software, has a privilege escalation vulnerability that allows a caller with pairing privileges but without admin privileges to approve pending device requests asking for broader scopes, including admin access. This vulnerability is due to the missing scope validation in the /pair approve command path. The issue affects OpenClaw versions before 2026.3.28. A CVE record has been updated with details of the vulnerability.