#VU125282 Improper privilege management in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to approve node pairing without proper privileges.
The vulnerability exists due to improper privilege management in the node.pair.approve method when handling pairing approval requests. A remote user can invoke the pairing approval operation with operator.write scope to approve node pairing without proper privileges.
For exec-capable nodes, the intended requirement includes the narrower pairing scope and an admin requirement.