<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:21:50 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32922 — OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32922</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, a caller holding only `operator.pairing` could use `device.token.rotate` to mint a new token with broader scopes for an already paired device. If the target device was approved for `operator.admin`, the attacker could obtain an administrative token without already holding administrative scope.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization flaw. On deployments with connected node hosts or companion apps that expose `system.run`, the escalated token could then modify node execution approvals and reach real remote code execution on the node. Even without nodes, the flaw still granted unauthorized gateway-admin access.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
`device.token.rotate` accepted caller-supplied target scopes and validated them against the target device&amp;#39;s approved scopes, but it did not constrain the newly minted scopes to the caller&amp;#39;s own current scope set. That allowed a pairing-scoped caller to mint a broader token for an already paired administrative device.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now enforces caller-scope subsetting in `device.token.rotate`, preventing callers from minting device tokens broader than the scopes they already hold. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, a caller holding only `operator.pairing` could use `device.token.rotate` to mint a new token with broader scopes for an already paired device. If the target device was approved for `operator.admin`, the attacker could obtain an administrative token without already holding administrative scope.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization flaw. On deployments with connected node hosts or companion apps that expose `system.run`, the escalated token could then modify node execution approvals and reach real remote code execution on the node. Even without nodes, the flaw still granted unauthorized gateway-admin access.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
`device.token.rotate` accepted caller-supplied target scopes and validated them against the target device&amp;#39;s approved scopes, but it did not constrain the newly minted scopes to the caller&amp;#39;s own current scope set. That allowed a pairing-scoped caller to mint a broader token for an already paired administrative device.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now enforces caller-scope subsetting in `device.token.rotate`, preventing callers from minting device tokens broader than the scopes they already hold. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32922</guid>
    </item>
    <item>
      <title>cnvd-2026-16698</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16698</link>
      <description>cnvd-2026-16698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16698</guid>
    </item>
    <item>
      <title>EUVD-2026-329471</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329471</link>
      <description>EUVD-2026-329471</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329471</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32922</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32922</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller&amp;#39;s current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller&amp;#39;s current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32922</guid>
    </item>
    <item>
      <title>GHSA-x8qx-w8w2-g4rx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8qx-w8w2-g4rx</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller&amp;#39;s current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller&amp;#39;s current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8qx-w8w2-g4rx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</guid>
    </item>
  </channel>
</rss>
