Добавить новость
123ru.net
Mashable
Апрель
2026
1 2 3 4 5 6 7 8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30

A frightening OpenClaw vulnerability has been discovered

0

If you've been using OpenClaw, the wildly popular AI agentic tool that took the developer community by storm, you should probably update it if you haven't done so already.

OpenClaw, as we've reported in the past, has widely known security problems. From the beginning, OpenClaw creator Peter Steinberger has warned potential users on GitHub that "There is no 'perfectly secure' setup."

Users can grant OpenClaw control over their devices and access to specific apps, local files, and logged-in accounts, allowing it to act on their behalf with full user permissions. That's the whole point of this agentic AI assistant. That's also why, as security researchers have been warning for months, it's a significant risk if something goes wrong.

Now, predictably, something went wrong.

According to Ars Technica, developers at OpenClaw patched three high-severity vulnerabilities early last week, the most serious of which — CVE-2026-33579 — scored 9.8 out of 10 on the severity scale. Researchers at AI app-builder Blink found that the flaw allowed anyone with the lowest possible level of access to silently upgrade themselves to full administrator.

The mechanics, as Blink described them, are straightforward. OpenClaw's device pairing system failed to verify whether the person approving an access request actually had the authority to grant the request. So, an attacker with basic pairing privileges could simply ask for admin access and approve their own request. The door was, functionally, unlocked from the inside.

Just how many users' Claw setups were vulnerable to takeover? Blink researchers reported that about 63 percent of internet-connected OpenClaw instances were running without any authentication. On those deployments, an attacker didn't even need a low-level account to get started — they could walk in off the street and work their way up to admin.

Ars Technica notes that the patch was released on Sunday, April 5, but the official CVE listing didn't appear until Tuesday. That two-day gap gave attackers who were paying attention a head start before most users would have known to update.

Blink noted that CVE-2026-33579 is the sixth pairing-related vulnerability disclosed in OpenClaw in six weeks — all variations on the same underlying design flaw in how the tool handles permissions. Each patch has addressed a specific exploit in isolation rather than rearchitecting the authorization system responsible for all of them.

If you're running OpenClaw, update to version 2026.3.28 immediately. If you were running an older version in the past week, Ars Technica and Blink both recommend treating your instance as potentially compromised and auditing your activity logs for suspicious device approvals.

Beyond that, it may be worth asking whether the productivity gains from a tool this powerful are worth the security risks that come with it.






Загрузка...


Губернаторы России

Спорт в России и мире

Загрузка...

Все новости спорта сегодня


Новости тенниса

Загрузка...


123ru.net – это самые свежие новости из регионов и со всего мира в прямом эфире 24 часа в сутки 7 дней в неделю на всех языках мира без цензуры и предвзятости редактора. Не новости делают нас, а мы – делаем новости. Наши новости опубликованы живыми людьми в формате онлайн. Вы всегда можете добавить свои новости сиюминутно – здесь и прочитать их тут же и – сейчас в России, в Украине и в мире по темам в режиме 24/7 ежесекундно. А теперь ещё - регионы, Крым, Москва и Россия.


Загрузка...

Загрузка...

Экология в России и мире




Путин в России и мире

Лукашенко в Беларуси и мире



123ru.netмеждународная интерактивная информационная сеть (ежеминутные новости с ежедневным интелектуальным архивом). Только у нас — все главные новости дня без политической цензуры. "123 Новости" — абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Smi24.net — облегчённая версия старейшего обозревателя новостей 123ru.net.

Мы не навязываем Вам своё видение, мы даём Вам объективный срез событий дня без цензуры и без купюр. Новости, какие они есть — онлайн (с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии).

123ru.net — живые новости в прямом эфире!

В любую минуту Вы можете добавить свою новость мгновенно — здесь.






Здоровье в России и мире


Частные объявления в Вашем городе, в Вашем регионе и в России






Загрузка...

Загрузка...





Друзья 123ru.net


Информационные партнёры 123ru.net



Спонсоры 123ru.net