---
id: CVE-2026-102806
title: >-
  OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in
  the Gateway's local media root allowlist that breaks filesystem isolation
  between sandboxed sessions
summary: >-
  OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in
  the Gateway's local media root allowlist that breaks filesystem isolation
  between sandboxed sessions. Sandboxed sessions or untrusted content can cause
  the Gat…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.9.5
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:13.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102806'
references:
  - url: 'https://docs.openclaw.ai/releases/2026.9.5'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media-understanding/runner.attachments.ts#L40-L50
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media/local-roots.ts#L33-L60
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/commit/fca04893b5b337d2eb70a6ba41f03fc8e33eff83
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw/pull/144347'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.9.5-sandbox-isolation-bypass-via-media-pipelines
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T17:41:02.258Z'
---

## Overview

OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
