CVE-2026-102806: OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines
OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.9.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs access as a sandboxed session or must be able to supply untrusted content that reaches Gateway media pipeline functions. Exploitation requires low privileges but is network-reachable and has high attack complexity.
What data could be exposed?
The affected media-path authorization can permit reads from sibling session sandboxes and shared workspace directories, rather than limiting reads to the active session. The reported impact is high confidentiality impact, with no stated integrity or availability impact.
Are all OpenClaw deployments affected by default?
The provided information identifies OpenClaw versions before 2026.9.5, but does not state whether the vulnerable media pipeline configuration is enabled or reachable by default.
How can I determine whether I am affected?
Check whether the deployed OpenClaw version is earlier than 2026.9.5 and whether sandboxed sessions or untrusted content can invoke Gateway media pipeline functions. The issue concerns local media root allowlist enforcement for reads outside the active session.