CVE-2026-32046: Openclaw
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leverage the disabled OS-level sandbox protections in the Chromium browser container to achieve code execution on the host system.
Affected products
- Openclaw Openclaw: before 2026.2.21 (fixed in 2026.2.21)
Published 2026-03-21. Last modified 2026-06-17.