Beveiligingsadvies

CVE-2026-27646

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-23 21:36:00
Laatst bijgewerkt 2026-07-14 18:39:37
Toegewezen door VulnCheck
CVSS-score 6.1
Status PUBLISHED

Beschrijving

OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from sandboxed chat context into host-side ACP session initialization when ACP is enabled.