
CVE-2026-44997 OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit … https://www.cve.org/CVERecord?id=CVE-2026-44997
Post summary
The snippet merely announces CVE‑2026‑44997, noting its technical nature but lacking evidence of PoC, exploitation, or remediation.
