Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

May 24, 2026

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

May 23, 2026

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

May 23, 2026
Facebook X (Twitter) Instagram
Sunday, May 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
News

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Team-CWDBy Team-CWDMay 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence.

The vulnerabilities, collectively dubbed

Claw Chain

by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below –


  • CVE-2026-44112

    (CVSS score: 9.6/6.3) – A time-of-check/time-of-use (TOCTOU) race condition vulnerability in the
    OpenShell
    managed sandbox backend that allows attackers to bypass sandbox restrictions and redirect writes outside the intended mount root. 

  • CVE-2026-44113

    (CVSS score: 7.7/6.3) – A TOCTOU race condition vulnerability in OpenShell that allows attackers to bypass sandbox restrictions and read files outside the intended mount root.

  • CVE-2026-44115

    (CVSS score: 8.8) – An incomplete list of disallowed inputs vulnerability that allows attackers to bypass allowlist validation by embedding shell expansion tokens in a
    here document
    (heredoc) body to execute unapproved commands at runtime.

  • CVE-2026-44118

    (CVSS score: 7.8) – An improper access control vulnerability that could allow non-owner loopback clients to impersonate an owner to elevate their privileges and gain control over gateway configuration, cron scheduling, and execution environment management.

Cyera said successful exploitation of CVE-2026-44112 could allow an attacker to tamper with configuration, plant backdoors, and establish persistent control over the compromised host, whereas CVE-2026-44113 could be weaponized to read system files, credentials, and internal artifacts.

The exploitation chain unfolds over four steps –

  • A malicious plugin, prompt injection, or compromised external input gains code execution inside the OpenShell sandbox.
  • Leverage CVE-2026-44113 and CVE-2026-44115 to expose credentials, secrets, and sensitive files.
  • Exploit CVE-2026-44118 to obtain owner-level control of the agent runtime.
  • Use CVE-2026-44112 to plant backdoors or make configuration changes and set up persistence.

The root cause for CVE-2026-44118, per the cybersecurity company, stems from the fact that OpenClaw trusts a client-controlled ownership flag called senderIsOwner, which signals whether the caller is authorized for owner-only tools, without validating it against the authenticated session.

“The MCP loopback runtime now issues separate owner and non-owner bearer tokens and derives senderIsOwner exclusively from which token authenticated the request,” OpenClaw detailed the fixes in an advisory for the flaw. “The spoofable sender-owner header is no longer emitted or trusted.”

Following responsible disclosure, all four vulnerabilities have been addressed in OpenClaw version 2026.4.22. Security researcher Vladimir Tokarev has been credited with discovering and reporting the issues. Users are advised to update to the latest version to stay protected against potential threats.

“By weaponizing the agent’s own privileges, an adversary moves through data access, privilege escalation, and persistence — using the agent as their hands inside the environment,” Cyera said. “Each step looks like normal agent behavior to traditional controls, broadening blast radius and making detection significantly harder.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhat 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
Next Article Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
Team-CWD
  • Website

Related Posts

News

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

May 24, 2026
News

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

May 23, 2026
News

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

May 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Mobile app permissions (still) matter more than you may think

February 27, 2026

Look out for phony verification pages spreading malware

September 14, 2025

How to help older family members avoid scams

October 31, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.