CVE-2026-102806
Published 29 September 2026 · tracked since 30 September 2026
Description
OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared wor
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95327 MEDIUM 6.5
- CVE-2026-95328 MEDIUM 6.5
- CVE-2026-95329 CRITICAL 9.6
- CVE-2026-95331 CRITICAL 9.6
- CVE-2026-95318 CRITICAL 9.6
- CVE-2026-95319 HIGH 8.3
- CVE-2026-95322 HIGH 8.3
- CVE-2026-95325 CRITICAL 9.6
- CVE-2026-95310 CRITICAL 9.6
- CVE-2026-95311 CRITICAL 9.6