CVE-2026-33579
2 mentions across all digests
Critical privilege escalation vulnerability (CVSS 8.6) in OpenClaw allowing any unauthenticated user to approve their own admin escalation and achieve full instance takeover in ~30 seconds, patched in version 2026.3.28.
OpenClaw gives users yet another reason to be freaked out about security
Critical privilege escalation in OpenClaw (CVE-2026-33579, CVSS 8.1–9.8) allows any user with pairing permission to escalate to admin and compromise all connected resources, affecting the 347k-star tool used for file, account, and messaging access.
If you're running OpenClaw, you probably got hacked in the last week
Critical OpenClaw vulnerability (CVE-2026-33579, CVSS 8.6) allows any unauthenticated user to self-escalate to admin in ~30 seconds; 135k+ instances exposed with zero authentication.