


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pai…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:19
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access
OpenClaw before version 2026.3.22 contains a privilege escalation vulnerability in its bootstrap setup process. The vulnerability occurs during device pairing when bootstrap setup codes are not properly bound to intended device roles and scopes. Attackers can exploit this weakness during first-use device pairing to escalate their privileges beyond their intended role and scope. This allows unauthorized access to higher-level system functions and potentially compromises the entire device security model. The vulnerability affects the initial setup phase making it particularly dangerous for new deployments.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41386
https://github.com/openclaw/openclaw/commit/a600c72ed7d0045a27f58bf031d2b36ecb0141c9
https://github.com/openclaw/openclaw/security/advisories/GHSA-gg9v-mgcp-v6m7
https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-unbound-bootstrap-setup-codes
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
