Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor
Uptime Monitor

OpenClaw Security Flaws Highlight Privilege Escalation Risk

Image © Arstechnica
A newly fixed OpenClaw vulnerability shows how attackers can escalate from pairing privileges to full admin access, potentially compromising entire deployments.

Security researchers are highlighting a newly fixed OpenClaw vulnerability as a stark reminder of what can happen when an AI agent platform operates with broad permissions.

OpenClaw, launched in November and now popular in the development community, is designed to interact with apps and resources across messaging platforms and local or cloud files, effectively acting as the user with their full permissions.

The fixed patch includes CVE-2026-33579, a high-severity flaw that lets someone with pairing privileges to elevate to operator.admin and gain administrative control over the OpenClaw instance.

Blink researchers explain that an attacker already holding operator.pairing could silently approve device pairings asking for operator.admin, enabling complete takeover without additional prompts.

In practical terms, a compromised admin device could read connected data sources, exfiltrate credentials, call arbitrary tools, and pivot to other services across the deployed OpenClaw environment.

Even with patches, analysts warn that many OpenClaw deployments may remain exposed or unpatched; organizations are advised to audit pairing approvals, limit permissions, and reassess use of OpenClaw until stronger access controls are in place.

 

Arstechnica

Notícias relacionadas

Irã ataca data center da Oracle em Dubai
Telefónica e TIM menos expostas à energia
Vivo lança crediário Vivo Pay
TIP Brasil lança vertical gamer para ISPs
Anderson Soares assume CAIO na AI Brasil
Telecom ficou entre os setores mais atacados, diz HPE

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais