CVE-2026-100589

8.3

OpenClaw · OpenClaw

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability that permits unauthorized access to host browser operations via paired nodes.

Executive summary

A high-severity sandbox bypass vulnerability in OpenClaw allows authenticated attackers to manipulate host browser profiles and session data.

Vulnerability

This is an incorrect authorization flaw (CWE-863) where the browser tool fails to enforce sandbox restrictions. An attacker with low-level authenticated access to the sandboxed agent can bypass configuration settings to execute host browser actions.

Business impact

The vulnerability carries a CVSS score of 8.3, reflecting the significant potential for unauthorized access to sensitive browser profiles and authenticated user states. If exploited, an attacker could hijack active sessions, exfiltrate private data, or perform actions on behalf of the user, leading to severe privacy violations and potential compromise of corporate accounts.

Remediation

Immediate Action: Update OpenClaw to version 2026.7.1 or later to implement the necessary authorization checks.

Proactive Monitoring: Review access logs for unusual browser node pairing activity or unexpected execution of host-level browser commands from within sandboxed sessions.

Compensating Controls: Ensure that sandbox configurations are strictly enforced at the network level and limit the ability of agents to pair with sensitive nodes until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high impact on session security and the ability to bypass intended authorization controls, this vulnerability poses a significant risk to organizations utilizing OpenClaw. Administrators should prioritize the deployment of version 2026.7.1 immediately to close the sandbox escape vector and prevent potential account takeover attempts.

More OpenClaw CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by wwwvwwvwwwwwvwwvw, per the CVE Program record.