Industry
Millions of AI agents imperiled by critical vulnerability in open source package
A critical vulnerability (CVE-2026-33579, scoring 9.8/10 severity) was discovered in the OpenClaw open source package, allowing attackers with minimal access to silently escalate privileges to full ad
A critical vulnerability (CVE-2026-33579, scoring 9.8/10 severity) was discovered in the OpenClaw open source package, allowing attackers with minimal access to silently escalate privileges to full administrator status. Approximately 63 percent of internet-connected OpenClaw instances were running without authentication, leaving millions of AI agents vulnerable to takeover. This was the sixth pairing-related vulnerability in OpenClaw within six weeks, stemming from underlying design flaws in the authorization system.
Source: Ars Technica | 2026-05-26