clawsmith.com/signal/cve-2026-32922-cvss-99-privilege-escalation-openclaw
⚠ IssueWide OpenLive
CVE-2026-32922: CVSS 9.9 Privilege Escalation Lets Any Paired Device Become Full Admin
OpenClaw's device.token.rotate function fails to constrain new token scopes to the caller's existing scope set. Any device with operator.pairing scope can request and receive operator.admin in one API call. CVSS 9.9. Fixed in v2026.3.11. 137 total security advisories tracked between February and April 2026.
Product Idea from this Signal
A CLI tool that audits OpenClaw device token scopes and blocks privilege escalation paths before attackers exploit them
2.1k ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Score Breakdown
HN
770
GitHub
158
Social Proof 2 sources
Frequently Asked Questions
Virality Score
928
across 0 platforms
Details
Signalissue
Ecosystem—
Sources2
Platforms0
Updated1d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →