PT-2026-26730 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-32048

CVSS v3.1

7.5

High

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2026-32048

Affected Products

Openclaw