clawsmith.com/signal/cve-2026-32922-privilege-escalation-token-rotation
⚠ IssueUnknownSecurityLive
CVE-2026-32922: Critical Privilege Escalation in OpenClaw Token Rotation (CVSS 9.9)
Token rotation function in device.token.rotate lacks scope validation, allowing any paired device with operator.pairing scope to mint operator.admin tokens and achieve RCE on all connected nodes. CVSS 9.9, published March 29 2026. 21,639 exposed instances identified by Censys.
Product Idea from this Signal
A security service that auto-patches OpenClaw CVEs within hours of disclosure before attackers exploit them
3.7k ▲SECURITYCLIDEVTOOLOPEN-SOURCESYSADMIN
CompetitiveView Opportunity →
Social Proof 4 sources
Frequently Asked Questions
Virality Score
0
across 5 platforms
Details
Signalissue
EcosystemSecurity
Sources4
Platforms5
Updated1d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →