Junglewise Threat Intelligence

CVE-2026-44997: OpenClaw security envelope constraint bypass in ACP child sessions

CVE-2026-44997 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software library used for managing subagents and sessions. A vulnerability exists where restricted subagents can bypass security constraints when creating new child sessions. This could allow a restricted user or process to exceed their intended operational limits, potentially leading to unauthorized actions or resource usage within the system.

Technical details

The vulnerability is classified as Insecure Inherited Permissions (CWE-277) within the OpenClaw npm package. When a restricted subagent spawns an Agent Control Protocol (ACP) child session, the system fails to carry forward security envelope constraints such as recursion depth, child-count limits, control scope, and target-agent restrictions. An attacker with low privileges can exploit this to bypass intended sandbox or resource constraints. The issue was addressed in version 2026.4.22 by ensuring ACP spawn operations resolve and persist child subagent envelope fields and enforce maximum depth and active-child caps.

Affected products

  • OpenClaw openclaw <= 2026.4.21

Timeline

  • 2026-04-23: disclosed: Advisory first published on GitHub
  • 2026-05-04: advisory: Published to GitHub Advisory Database
  • 2026-05-19: other: Advisory updated

References

Related threats