security
May 16, 2026
By Teun
Four OpenClaw flaws exposed data, privileges, and persistence
Cyera says four chainable OpenClaw vulnerabilities, dubbed Claw Chain, could let attackers steal data, escalate privileges, and plant backdoors. OpenClaw says the issues affect its OpenShell sandbox backend and MCP loopback runtime and were fixed in version 2026.4.22.
Cybersecurity researchers at Cyera have disclosed four vulnerabilities in OpenClaw that can be chained to steal sensitive data, escalate privileges, and establish persistent control over a compromised host. The company said the flaws, which it dubbed “Claw Chain,” affected OpenClaw’s OpenShell managed sandbox backend and its MCP loopback runtime.
OpenClaw has patched all four issues in version 2026.4.22. Cyera said the vulnerabilities can be combined in a sequence that starts with code execution inside the sandbox and ends with control outside it.
According to Cyera, the first step in the attack chain is getting code execution inside the OpenShell sandbox through a malicious plugin, prompt injection, or compromised external input. Once inside, attackers can use two of the bugs, tracked as CVE-2026-44113 and CVE-2026-44115, to expose credentials, secrets, and sensitive files.
The next step is CVE-2026-44118, which Cyera described as a flaw in how OpenClaw handled ownership. The issue comes from the agent trusting a client-controlled flag called senderIsOwner without checking it against the authenticated session.
That meant a non-owner loopback client could impersonate an owner and gain control over gateway configuration, cron scheduling, and execution environment management. OpenClaw’s fix, according to the advisory, is to issue separate owner and non-owner bearer tokens and derive senderIsOwner only from the authenticating token, not from a spoofable header.
The most severe bug is CVE-2026-44112, which carries a CVSS score of 9.6. Cyera said it is a time-of-check/time-of-use, or TOCTOU, race condition that lets attackers bypass sandbox restrictions and redirect file writes or reads outside the intended mount root.
Cyera also said CVE-2026-44113 is a TOCTOU race condition that can be used to redirect file access outside the sandbox boundary. CVE-2026-44115 is an incomplete allowlist issue that allows shell expansion tokens to be embedded inside a heredoc body, which can trigger commands that runtime checks would otherwise block.
Cyera said the result is especially dangerous because the malicious activity can look like normal agent behaviour to standard security tools. “By weaponizing the agent’s own privileges, an adversary moves through data access, privilege escalation, and persistence, using the agent as their hands inside the environment,” the company said.
OpenClaw’s sandbox is designed to contain agent activity, but Cyera said these flaws let an attacker work through that protection rather than around it. That broadens the blast radius and makes detection harder because the actions resemble legitimate agent operations.
The disclosure comes after other security issues involving OpenClaw this year. In January, researchers reported CVE-2026-25253, a remote code execution flaw that allowed any website a user visited to silently connect to the agent’s local server through an unvalidated WebSocket, according to the earlier report.
A separate Koi Security audit of ClawHub, OpenClaw’s skill marketplace, found 341 malicious entries out of 2,857 available skills. Those entries were designed to steal credentials, open reverse shells, and hijack agents for cryptocurrency mining, according to the audit.
Nvidia addressed some broader security concerns in March with NemoClaw, an enterprise layer that adds sandbox orchestration, privacy guardrails, and security hardening on top of OpenClaw. Nvidia said it built the product with Cisco, CrowdStrike, Google, and Microsoft Security.
Cyera said NemoClaw operates at the infrastructure level, not the application level, so Claw Chain still lived inside OpenClaw’s own sandbox implementation before the patch. The company also said OpenClaw has more than 3.2 million users, is integrated with ChatGPT subscriptions through OpenAI, and has been adopted by Nvidia and Tencent as an enterprise platform.
Security researcher Vladimir Tokarev was credited with finding and reporting the flaws. OpenClaw said users should update to version 2026.4.22 immediately.