OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf worker can steer or kill sibling runs and cause execution with broader tool policies by exploiting insufficient authorization checks on subagent control requests.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-29 13:16
Updated : 2026-03-30 13:26
NVD link : CVE-2026-32915
Mitre link : CVE-2026-32915
CVE.ORG link : CVE-2026-32915
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
