CVE-2026-35639 | OpenClaw up to 2026.3.21 device.pair.approve incorrect privileged apis (GHSA-hf68-49fm-59cq / WID-SEC-2026-0856)
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21. This vulnerability affects the function device.pair.approve. Such manipulation leads to incorrect use of privileged apis.
This vulnerability is traded as CVE-2026-35639. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.