Loading
Generated remediation guidance and an executive summary. No account required.
OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.pairing scope, allowing unprivileged users to approve node pairing. Attackers with operator.write permissions can bypass pairing approval restrictions to gain unauthorized access to exec-capable nodes.
No affected products information available.
Use CWE-863 to widen CVE-2026-42426 into its surrounding weakness, vendor, and product context.