news.volyx.in

OpenClaw privilege escalation vulnerability (nvd.nist.gov)

514 points by kykeonaut · 150 days ago · 256 comments on HN

Article summary

OpenClaw, a software, has a privilege escalation vulnerability that allows a caller with pairing privileges but without admin privileges to approve pending device requests asking for broader scopes, including admin access. This vulnerability is due to the missing scope validation in the /pair approve command path. The issue affects OpenClaw versions before 2026.3.28. A CVE record has been updated with details of the vulnerability.

Main themes

  • OpenClaw vulnerability
  • security risks
  • configuration and maintenance
  • default settings
  • exploitation methods
  • semantics and terminology

What commenters say

  • Some commenters believe that OpenClaw's security issues make it a risky software to use, especially for those who are not tech-savvy.
  • Others argue that the software can be used safely if properly configured and maintained.
  • There is a disagreement about the default configuration of OpenClaw and whether it exposes the instance to the internet.
  • Some think that the number of affected instances is exaggerated, while others believe that the vulnerability is a serious issue that affects a significant number of users.
  • A few commenters suggest that the vulnerability is not a major concern if the instance is not publicly exposed, but others point out that it can still be exploited through malicious websites or other means.
  • The discussion also touches on the topic of semantics, with some arguing over the meaning of the word 'probably' in the context of the vulnerability's impact.