clawsmith.com/signal/cve-2026-32922-critical-privilege-escalation-cvss-9-9
⚠ IssueWide OpenLive
CVE-2026-32922: One API Call Grants Full Admin + RCE on OpenClaw (CVSS 9.9)
CVE-2026-32922, disclosed March 29 2026, is the most severe OpenClaw vulnerability to date (CVSS 9.9). A single API call to device.token.rotate with operator.pairing scope can mint operator.admin tokens, enabling remote code execution on all connected nodes. Fixed in v2026.3.11.
Product Idea from this Signal
A CLI tool that audits OpenClaw device token scopes and blocks privilege escalation paths before attackers exploit them
2.1k ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Score Breakdown
HN
694
Social Proof 5 sources
Frequently Asked Questions
Virality Score
694
across 0 platforms
Details
Signalissue
Ecosystem—
Sources5
Platforms0
Updated22d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →