No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 29 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf worker can steer or kill sibling runs and cause execution with broader tool policies by exploiting insufficient authorization checks on subagent control requests. | |
| Title | OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surface | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-30T15:57:31.184Z
Reserved: 2026-03-16T21:19:31.965Z
Link: CVE-2026-32915
Updated: 2026-03-30T15:57:25.877Z
Status : Awaiting Analysis
Published: 2026-03-29T13:16:59.973
Modified: 2026-03-30T13:26:07.647
Link: CVE-2026-32915
No data.
OpenCVE Enrichment
Updated: 2026-03-30T06:58:27Z