#VU125144 Improper privilege management in OpenClaw - CVE-2026-32922
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escalate privileges and execute arbitrary code.
The vulnerability exists due to improper privilege management in device.token.rotate when rotating device tokens for an already paired device. A remote user can mint a token with broader scopes than their own to escalate privileges and execute arbitrary code.
Exploitation can reach node-level code execution on deployments with connected node hosts or companion apps that expose system.run; otherwise, the issue grants unauthorized gateway-admin access.