Four OpenClaw Flaws Could Enable Theft and Persistence

Cyera says four OpenClaw vulnerabilities, nicknamed Claw Chain, can be chained to steal data, escalate privileges, and maintain persistence. OpenClaw says the issues were fixed in version 2026.4.22 and credits researcher Vladimir Tokarev for reporting them.

Four OpenClaw Flaws Could Enable Theft and Persistence

Cybersecurity researchers have disclosed four OpenClaw vulnerabilities that can be chained to give an attacker data theft, privilege escalation, and persistence inside an affected environment. Cyera said the flaws, which it calls Claw Chain, could let an attacker gain a foothold, expose sensitive files, and plant backdoors.

The issues affect OpenShell, the managed sandbox backend used by OpenClaw. According to Cyera, two of the flaws are time-of-check/time-of-use, or TOCTOU, race conditions. That type of bug happens when software checks whether an action is allowed, then performs the action later, giving an attacker a chance to change conditions in between.

⚡ New to this?

These bugs matter because they could let an attacker abuse an AI agent environment from the inside, not just crash it from the outside. TOCTOU means the software checks permission at one moment and acts later, which creates a timing gap attackers can exploit. If a system trusts the wrong ownership signal, a non-owner can end up acting like an administrator.

🦞 OpenClaw angle

If you run OpenClaw, update to version 2026.4.22 immediately and verify that all deployed instances are patched, not just the main server. Review any plugins, prompt inputs, and external connectors that can feed commands into OpenShell, because Cyera’s chain starts with code execution inside the sandbox. Also check whether any automation depends on owner-only actions such as gateway settings, cron jobs, or execution environment changes, and rotate credentials if you find evidence of exposure.

The first flaw, tracked as CVE-2026-44112, has a CVSS score of 9.6/6.3 and can let attackers bypass sandbox restrictions and redirect writes outside the intended mount root. Cyera said that could allow tampering with configuration files, planting backdoors, and establishing persistent control on the compromised host.

The second flaw, CVE-2026-44113, has a CVSS score of 7.7/6.3 and can let attackers bypass sandbox restrictions and read files outside the intended mount root. According to the company, that could expose system files, credentials, and internal artifacts.

The third flaw, CVE-2026-44115, has a CVSS score of 8.8 and involves an incomplete list of disallowed inputs. Cyera said an attacker can bypass allowlist validation by embedding shell expansion tokens in a here document, or heredoc, body and then execute unapproved commands at runtime.

The fourth issue, CVE-2026-44118, has a CVSS score of 7.8 and is an improper access control flaw. Cyera said it could let non-owner loopback clients impersonate an owner and gain control over gateway configuration, cron scheduling, and execution environment management.

Cyera said the root cause of CVE-2026-44118 is that OpenClaw trusted a client-controlled ownership flag called senderIsOwner without checking it against the authenticated session. In its advisory, OpenClaw said the loopback runtime now issues separate owner and non-owner bearer tokens and derives senderIsOwner only from the token used to authenticate the request. The company also said the spoofable sender-owner header is no longer emitted or trusted.

According to Cyera, the attack chain can unfold in four steps. First, a malicious plugin, prompt injection, or compromised external input gets code execution inside the OpenShell sandbox. Next, the attacker uses CVE-2026-44113 and CVE-2026-44115 to expose credentials, secrets, and sensitive files.

From there, CVE-2026-44118 can be used to obtain owner-level control of the agent runtime. Finally, CVE-2026-44112 can be used to plant backdoors or make configuration changes and set up persistence.

OpenClaw said all four vulnerabilities were fixed in version 2026.4.22 following responsible disclosure. Security researcher Vladimir Tokarev was credited with discovering and reporting the issues. The company advised users to update to the latest version to stay protected.

Source: The Hacker News ↗

More from Security News