The security of autonomous AI agents is back in the spotlight after cybersecurity researchers at Cyera uncovered four critical vulnerabilities in OpenClaw . The flaws, collectively dubbed “ Claw Chain ,” allow an attacker to gain access to sensitive data, escalate privileges , and ultimately maintain permanent control over compromised systems.

The vulnerabilities affect the backend sandbox used by OpenClaw's OpenShell, as well as the MCP loopback runtime. According to the researchers, the risk of the attack chain is particularly high, as the malicious actions look almost identical to the legitimate operations of an AI agent, making it significantly more difficult to detect by traditional security tools.
The OpenClaw team confirmed that all four issues have been fixed in version 2026.4.22, however millions of users may remain exposed due to older installations.
OpenClaw: How the “Claw Chain” attack chain works
The attack progresses in four successive stages, exploiting different vulnerabilities to achieve a complete breach of the environment.
The first step begins when an attacker gains execution inside the OpenShell sandbox. This can happen via a malicious plugin, prompt injection , or compromised external input.
See also: NGINX: Critical vulnerability used in attacks
Then CVE-2026-44113 and CVE-2026-44115, which allow the disclosure of credentials, secret files, and other sensitive data that should normally be protected by the sandbox.
The third stage is considered particularly critical from an architectural perspective. CVE-2026-44118 exploits an ownership control mechanism within the OpenClaw runtime, allowing an attacker to gain owner-level control of the agent environment.
Finally, CVE-2026-44112 — the most serious flaw in the chain with a CVSS score of 9.6 — is used for persistence outside of the sandbox, installation of backdoors , and permanent modification of the host system configuration.
The vulnerability that worries researchers the most
Among the four vulnerabilities, CVE-2026-44118 is considered the most concerning by design. The issue arises because OpenClaw trusts a client-controlled flag called “senderIsOwner” without properly verifying the authentication session.
Simply put, any non-owner loopback client could falsely present itself as the owner of the runtime and gain access to critical functions such as configuration management, cron scheduling, and control of the execution environment.
The implemented fix completely changes the authentication logic, introducing separate owner and non-owner authentication tokens, while ownership information is now generated exclusively from the auth token and not from client headers that can be forged.

TOCTOU vulnerabilities and sandbox bypass
Of particular interest are the two TOCTOU vulnerabilities — known as “Time-of-Check/Time-of-Use” flaws — which were recorded as CVE-2026-44112 and CVE-2026-44113.
Attacks of this type exploit the time gap between the security check and the actual use of a resource. In the case of OpenClaw, attackers were able to redirect file reads and writes outside the intended root sandbox area, completely bypassing security restrictions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Microsoft: Rejects report of critical Azure Backup vulnerability
CVE -2026-44115, on the other hand, uses shell expansion tokens within heredoc payloads, allowing command execution that would normally be blocked by the runtime environment.
Cyera researchers emphasize that the real danger of Claw Chain lies in the fact that the attacks are carried out using the AI agent's own privileges. Essentially, the attacker turns the agent into "digital hands" within the user's environment.
The growing security crisis surrounding OpenClaw
This is not the first time OpenClaw has been targeted by security researchers. In January, a critical RCE vulnerability, CVE-2026-25253, was disclosed, which allowed malicious websites to silently connect to the local agent server via unauthenticated WebSockets.
Meanwhile, a Koi Security of the ClawHub marketplace revealed 341 malicious “skills” among 2,857 available apps. The attacks included credential theft, reverse shells, and cryptomining hijacks.

Nvidia attempted to address some of the issues through NemoClaw , an enterprise-grade security platform developed in partnership with Cisco, CrowdStrike, Google, and Microsoft Security . However, NemoClaw operates primarily at the infrastructure orchestration level rather than application sandboxing, meaning that the Claw Chain vulnerabilities were affecting even hardened deployments before the patches were released.
See also: WordPress: Hackers exploit Burst Statistics vulnerability
The big problem of the era of AI agents
The Claw Chain case highlights a much broader issue that is beginning to seriously concern the artificial intelligence industry: AI agents now have access to files, API keys, credentials, cloud infrastructure and corporate data.
When such an agent is compromised, the consequences are practically the same as a complete breach of the user themselves or even the entire organization.
Traditional perimeter security was designed for human users, not autonomous software executing instructions from external sources in real time. Claw Chain may be the incident that forces the industry to finally treat the security of AI agents with the same seriousness that operating systems and cloud infrastructures are treated today.
