clawsmith.com/signal/cve-2026-32922-cvss-99-privilege-escalation-openclaw
⚠ IssueWide OpenLive
CVE-2026-32922: CVSS 9.9 Privilege Escalation Lets Any Paired Device Become Full Admin
OpenClaw's device.token.rotate function fails to constrain new token scopes to the caller's existing scope set. Any device with operator.pairing scope can request and receive operator.admin in one API call. CVSS 9.9. Fixed in v2026.3.11. 137 total security advisories tracked between February and April 2026.
Product Idea from this Signal
A CLI tool that audits OpenClaw device token scopes and blocks privilege escalation paths before attackers exploit them
920 ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Score Breakdown
HN
770
GitHub
150
Social Proof 2 sources
Frequently Asked Questions
Virality Score
920
across 0 platforms
Details
Signalissue
Ecosystem—
Sources2
Platforms0
Updated1d ago
Trend→ stable
Top ideas
All ideas →