OpenClaw gives users yet another reason to be freaked out about security

TL;DR AI
2 min readKey summary
OpenClaw has 347,000 stars on GitHub.
It was introduced in November.
Three high-severity vulnerabilities were fixed by security patches.
CVE-2026-33579 lets users with pairing privileges escalate to administrative status; severity rated 8.1–9.8. An attacker with operator.pairing scope can silently approve pairing requests that request operator.admin scope.
Once a pairing is approved, the attacker gains full administrative access to the OpenClaw instance without a secondary exploit; Blink researchers say the practical impact is severe.



