CVE-2026-44997: OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers can exploit this by spawning child sessions that bypass subagent-only constraints, potentially escalating privileges or accessing restricted resources.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44997?
CVE-2026-44997 has been classified as a significant security risk due to its capacity to bypass critical envelope constraints in child sessions.
How do I fix CVE-2026-44997?
To mitigate CVE-2026-44997, upgrade OpenClaw to version 2026.4.22 or later.
What types of systems are affected by CVE-2026-44997?
CVE-2026-44997 affects OpenClaw versions prior to 2026.4.22 running on Node.js environments.
What impacts can occur if CVE-2026-44997 is exploited?
Exploitation of CVE-2026-44997 could allow unauthorized subagents to create ACP child sessions with insufficient restrictions.
Is there a way to detect CVE-2026-44997 in my environment?
To detect CVE-2026-44997, check for versions of OpenClaw that are below 2026.4.22 and review session configurations for vulnerabilities.