Improper access control in OpenClaw - #VU127183
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass subagent security envelope constraints.
The vulnerability exists due to improper access control in ACP child session handling when spawning an ACP child session from a restricted subagent. A remote user can spawn a child session to bypass subagent security envelope constraints.
The issue affects subagent-only constraints such as depth, child-count limits, control scope, and target-agent restrictions.