
🚨 LIVE HIJACK ALERT — CVE-2026-34512. CVSS 8.1. any authenticated user can kill any subagent session. no scope validation. attackers gain admin termination rights with zero privilege escalation. OpenClaw pre-2026.3.25. investigating. 🧵
Post summary
CVE-2026-34512 in OpenClaw allows authenticated users to terminate any subagent session, and is currently being actively exploited in the wild.

