Privilege Escalation Vulnerability in OpenClaw by OpenClaw
CVE-2026-42432

7.3HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-42432?

OpenClaw prior to version 2026.4.8 is susceptible to a vulnerability that allows an attacker to exploit previously paired nodes. By circumventing the necessary re-pairing authentication, an attacker can execute privileged commands on the local assistant system without administrative permissions. This security weakness poses significant risks, enabling unauthorized access and control over the device.

Affected Version(s)

OpenClaw 0 < 2026.4.8

OpenClaw 2026.4.8

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
.