CVE-2026-41329: OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbox restrictions and achieve unauthorized privilege escalation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41329?
CVE-2026-41329 has a high severity due to its ability to allow privilege escalation through sandbox bypass.
How do I fix CVE-2026-41329?
To fix CVE-2026-41329, upgrade OpenClaw to version 2026.3.31 or later, which addresses this vulnerability.
What are the consequences of CVE-2026-41329 exploitation?
Exploitation of CVE-2026-41329 can lead to unauthorized access and privilege escalation, compromising the security of the affected system.
Who is affected by CVE-2026-41329?
CVE-2026-41329 affects all versions of OpenClaw prior to 2026.3.31.
What type of vulnerability is CVE-2026-41329?
CVE-2026-41329 is a sandbox bypass vulnerability that allows for privilege escalation.