<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:32:13.247312+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32922</id>
    <title>BREW-openclaw-cli-CVE-2026-32922 — OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE</title>
    <updated>2026-10-03T10:32:13.354904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
In affected versions of `openclaw`, a caller holding only `operator.pairing` could use `device.token.rotate` to mint a new token with broader scopes for an already paired device. If the target device was approved for `operator.admin`, the attacker could obtain an administrative token without already holding administrative scope.</p>
<p>## Impact
This is a critical authorization flaw. On deployments with connected node hosts or companion apps that expose `system.run`, the escalated token could then modify node execution approvals and reach real remote code execution on the node. Even without nodes, the flaw still granted unauthorized gateway-admin access.</p>
<p>## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.3.8`
- Fixed in: `2026.3.11`</p>
<p>## Technical Details
`device.token.rotate` accepted caller-supplied target scopes and validated them against the target device's approved scopes, but it did not constrain the newly minted scopes to the caller's own current scope set. That allowed a pairing-scoped caller to mint a broader token for an already paired administrative device.</p>
<p>## Fix
OpenClaw now enforces caller-scope subsetting in `device.token.rotate`, preventing callers from minting device tokens broader than the scopes they already hold. The fix shipped in `openclaw@2026.3.11`.</p>
<p>## Workarounds
Upgrade to `2026.3.11` or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16698</id>
    <title>cnvd-2026-16698</title>
    <updated>2026-10-03T10:32:13.354980+00:00</updated>
    <content>cnvd-2026-16698</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329471</id>
    <title>EUVD-2026-329471</title>
    <updated>2026-10-03T10:32:13.354999+00:00</updated>
    <content>EUVD-2026-329471</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32922</id>
    <title>fkie_cve-2026-32922</title>
    <updated>2026-10-03T10:32:13.355012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x8qx-w8w2-g4rx</id>
    <title>GHSA-x8qx-w8w2-g4rx</title>
    <updated>2026-10-03T10:32:13.355037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x8qx-w8w2-g4rx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</id>
    <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:32:13.355055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711"/>
  </entry>
</feed>
