CVE-2026-32018: OpenClaw < 2026.2.19 - Race Condition in Sandbox Registry Write Operations
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without locking to cause registry updates to lose data, resurrect removed entries, or corrupt sandbox state affecting list, prune, and recreate operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32018?
The severity of CVE-2026-32018 is classified as critical due to the potential for unauthorized access and data corruption.
How do I fix CVE-2026-32018?
To fix CVE-2026-32018, upgrade OpenClaw to version 2026.2.19 or later.
What types of operations are affected by CVE-2026-32018?
CVE-2026-32018 affects the concurrent updateRegistry and removeRegistryEntry operations in OpenClaw.
Who can exploit CVE-2026-32018?
CVE-2026-32018 can be exploited by attackers who can access sandbox containers and browsers running vulnerable versions of OpenClaw.
What kind of vulnerability is CVE-2026-32018?
CVE-2026-32018 is a race condition vulnerability that occurs in unsynchronized read-modify-write operations.