
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42432 is a privilege escalation vulnerability in OpenClaw (npm package) affecting all versions up to and including 2026.4.5, fixed in version 2026.4.8. The flaw allows previously paired nodes to reconnect with exec-capable commands without requiring the operator.admin scope, effectively bypassing re-pairing authentication. It was published on April 28, 2026, with a patch released on April 8, 2026. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (GitHub Advisory, Feedly).
The root cause is classified as CWE-863 (Incorrect Authorization): the node reconnection logic fails to enforce the operator.admin scope check when a previously paired node re-establishes a connection, allowing it to issue a broader command set including exec-capable commands. The attack vector is local (AV:L) with low privileges required and no user interaction needed. An attacker must have previously paired a node with the target OpenClaw instance and retain local access to the system to exploit the flaw. The fix, applied in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5, addresses the authorization boundary in the node pairing reconnect path (GitHub Advisory, GitHub Commit).
Successful exploitation allows a low-privileged local attacker to execute privileged (exec-capable) commands on the OpenClaw local assistant system without proper authorization. This can result in high confidentiality, integrity, and availability impact — including unauthorized access to sensitive data, system manipulation, and service disruption. Because OpenClaw is described as a user-controlled local assistant (not a multi-tenant service), the scope of impact is bounded to the local system, though complete system compromise remains a realistic outcome (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.022% (0.000220), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researchers @zsxsoft and @KeenSecurityLab (GitHub Advisory).
operator.admin scope requirement.operator.admin authorization) through the established session.Upgrade OpenClaw (npm) to version 2026.4.8 or later, which contains the security fix applied in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5. As interim measures, administrators should audit all currently paired nodes and revoke any suspicious or unrecognized pairings, implement additional access controls around node pairing mechanisms, and consider network segmentation to restrict local access to OpenClaw systems. There is no documented configuration-only workaround that fully mitigates the vulnerability without patching (GitHub Advisory, GitHub Commit).
The vulnerability was credited to researchers @zsxsoft and @KeenSecurityLab in the official GitHub Security Advisory, and was published by maintainer @steipete (GitHub Advisory). A brief post appeared on Bluesky via the CVE tracking account shortly after disclosure. Coverage was also noted on InfinitSec and INCIBE-CERT, indicating moderate community awareness but no significant controversy or widespread media coverage (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."