Security Advisory

CVE-2026-42432

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-28 18:10:20
Last updated 2026-05-26 11:52:18
Assigner VulnCheck
CVSS score 7.3
State PUBLISHED

Description

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without the operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.