OpenClaw lets attackers gain admin access without authentication. The tool, popular on GitHub, contains a flaw that bypasses login checks, allowing silent privilege escalation. Security teams should audit third‑party AI agents for hidden escalation paths and enforce strict authentication layers. This incident underscores the risk of relying on unverified AI tools for critical operations.