CVE-2026-102806: OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines

Published Sep 29, 2026
·
Updated

OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.

Affected Software

1 affected component
OpenClaw OpenClaw<2026.9.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.9.5

Event History

Sep 29, 2026
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Apr 18, 58715
Event
via NVD·06:00 PM

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs access as a sandboxed session or must be able to supply untrusted content that reaches Gateway media pipeline functions. Exploitation requires low privileges but is network-reachable and has high attack complexity.

2

What data could be exposed?

The affected media-path authorization can permit reads from sibling session sandboxes and shared workspace directories, rather than limiting reads to the active session. The reported impact is high confidentiality impact, with no stated integrity or availability impact.

3

Are all OpenClaw deployments affected by default?

The provided information identifies OpenClaw versions before 2026.9.5, but does not state whether the vulnerable media pipeline configuration is enabled or reachable by default.

4

How can I determine whether I am affected?

Check whether the deployed OpenClaw version is earlier than 2026.9.5 and whether sandboxed sessions or untrusted content can invoke Gateway media pipeline functions. The issue concerns local media root allowlist enforcement for reads outside the active session.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203