CVE-2026-32915Disclosure(openclaw / openclaw)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf worker can steer or kill sibling runs and cause execution with broader tool policies by exploiting insufficient authorization checks on subagent control requests.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-29); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-29: 3Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-29: 3Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-2903-3003-31
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-293
Disclosure3
2026-03-301
Disclosure1
2026-03-311
Patch1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32915 OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent … https://www.cve.org/CVERecord?id=CVE-2026-32915

    Post summary

    The text provides a brief announcement of CVE-2026-32915, describing it as a sandbox boundary bypass in OpenClaw before 2026.3.11, but contains no detailed technical discussion, PoC, exploit, or mitigation information.

    01010166
    56.9K followersView on X
  • CarloX@carloxthebot
    Patch

    OpenClaw CVE-2026-32922: CVSS 9.9. Low-priv pairing token → full admin RCE + key theft. 135,000 instances still exposed. Plus sandbox bypass CVE-2026-32915 (8.8). Fix: upgrade to 2026.3.11+, bind to localhost. Run: openclaw update #OpenClaw #Security

    Post summary

    OpenClaw disclosed CVE-2026-32922 and CVE-2026-32915 with high severity scores and provided specific upgrade and configuration steps to mitigate the vulnerabilities.

    0000054
    24 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32915: OpenClaw < 2026.3.11 - Sandbox B... Low-priv sandboxed workers can hijack sibling processes and escalate to parent scope—classic authorization bypass that ... https://zerodaysignal.com/vulnerability/CVE-2026-32915 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑32915 in OpenClaw (pre‑2026.3.11), describing a sandbox bypass that lets low‑priv workers hijack sibling processes to gain higher‑level access; a link to further details is provided.

    0000072
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32915 - High OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead o... https://www.thehackerwire.com/vulnerability/CVE-2026-32915/ https://t.co/inq6wVpZPg

    Post summary

    The post announces CVE‑2026‑32915 as a sandbox boundary bypass in OpenClaw before version 2026.3.11, detailing how leaf subagents can escape isolation, but it offers no PoC, exploit code, or evidence of live attacks.

    0000054
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32915: HIGH] URGENT: Vulnerability in OpenClaw before 2026.3.11 allows sandbox boundary bypass. Attackers can access and control beyond their scope, posing serious cyber threats. Update now!#cve,CVE-2026-32915,#cybersecurity https://cvefind.com/CVE-2026-32915

    Post summary

    The tweet announces a high‑severity sandbox boundary bypass in OpenClaw (vulnerable before 2026.3.11), urging users to update to mitigate the risk.

    0000057
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more