CVE-2026-32915

HIGH

OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surface

Title source: cna

Description

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf worker can steer or kill sibling runs and cause execution with broader tool policies by exploiting insufficient authorization checks on subagent control requests.

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (3)
OpenClaw/OpenClaw < 2026.3.11
openclaw/openclaw < 2026.3.11
OpenClaw/OpenClaw 2026.3.11
Published Mar 29, 2026
Tracked Since Mar 29, 2026