Junglewise Threat Intelligence

CVE-2026-32915: OpenClaw leaf subagents sandbox boundary bypass

CVE-2026-32915 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent framework that uses sandboxed subagents to execute tasks with restricted permissions. A vulnerability allowed low-privilege sandboxed workers to break out of their isolation and gain control over sibling worker sessions, potentially causing them to execute with elevated tool access. This is a critical sandbox escape that could enable privilege escalation and unauthorized operations within a shared multi-tenant environment.

Technical details

The vulnerability stems from improper privilege management (CWE-269) in OpenClaw's subagent control authorization layer. Leaf subagents incorrectly retained the subagents control tool and subagent control requests were authorized against the parent requester scope rather than being scoped to the caller's own spawned descendants. The control path only prevented self-targeting but did not restrict cross-sibling steering or kill operations. An attacker with access to a sandboxed leaf subagent could invoke steer or kill operations against sibling runs owned by the same requester, causing those runs to execute with the attacker's broader tool policy. The fix (openclaw@2026.3.11) removes subagents control access from leaf subagents by default, scopes subagent control strictly to the caller's own descendants, and rejects operations targeting runs outside that tree.

Affected products

  • OpenClaw openclaw <= 2026.3.8

Timeline

  • 2026-03-13: disclosed: Advisory published
  • 2026-03-12: patched: Fixed in openclaw@2026.3.11

References