New CVE-2026-33579 Vulnerability Exposes OpenClaw to Full Instance Takeover

Security researchers are urging OpenClaw users to assume compromise after a newly patched vulnerability — CVE-2026-33579 — allowed complete instance takeover with just low-level pairing permissions.

The flaw, rated 8.1–9.8 CVSS depending on the metric, was fixed earlier this week. But the implications are severe: anyone who already held operator.pairing scope — the lowest meaningful permission in an OpenClaw deployment — could silently approve device pairing requests requesting operator.admin scope. No secondary exploit, no user interaction required beyond the initial pairing step.

The impact, as researchers from Blink described it:

“An attacking device holds full administrative access to the OpenClaw instance… a compromised operator.admin device can read all connected data sources, exfiltrate credentials stored in the agent’s skill environment, execute arbitrary tool calls, and pivot to other connected services. The word ‘privilege escalation’ undersells this: the outcome is full instance takeover.”

For organizations running OpenClaw as a company-wide AI agent platform, a single compromised device means an attacker can read everything the agent has access to — Telegram, Discord, files, credentials, and more.

Background context: OpenClaw now sits at 347,000 GitHub stars and has seen explosive adoption since launching in November. The tool by design takes broad control of a user’s machine to be useful — which also makes security vulnerabilities particularly dangerous. Earlier this year, a Meta executive warned employees to keep OpenClaw off work laptops or face termination, calling it too unpredictable for secure environments.

This is at least the second major CVE disclosed in the past month, following CVE-2026-25253 (critical RCE) reported in late March.

Sources:

← Back to News