HomeSecurityClaw Chain: OpenClaw vulnerabilities allow complete system compromise

Claw Chain: OpenClaw vulnerabilities allow complete system compromise

The security of autonomous AI agents is back in the spotlight after cybersecurity researchers at Cyera uncovered four critical vulnerabilities in OpenClaw . The flaws, collectively dubbed “ Claw Chain ,” allow an attacker to gain access to sensitive data, escalate privileges , and ultimately maintain permanent control over compromised systems.

Claw Chain OpenClaw

The vulnerabilities affect the backend sandbox used by OpenClaw's OpenShell, as well as the MCP loopback runtime. According to the researchers, the risk of the attack chain is particularly high, as the malicious actions look almost identical to the legitimate operations of an AI agent, making it significantly more difficult to detect by traditional security tools.

The OpenClaw team confirmed that all four issues have been fixed in version 2026.4.22, however millions of users may remain exposed due to older installations.

OpenClaw: How the “Claw Chain” attack chain works

The attack progresses in four successive stages, exploiting different vulnerabilities to achieve a complete breach of the environment.

The first step begins when an attacker gains execution inside the OpenShell sandbox. This can happen via a malicious plugin, prompt injection , or compromised external input.

See also: NGINX: Critical vulnerability used in attacks

Then CVE-2026-44113 and CVE-2026-44115, which allow the disclosure of credentials, secret files, and other sensitive data that should normally be protected by the sandbox.

The third stage is considered particularly critical from an architectural perspective. CVE-2026-44118 exploits an ownership control mechanism within the OpenClaw runtime, allowing an attacker to gain owner-level control of the agent environment.

Finally, CVE-2026-44112 — the most serious flaw in the chain with a CVSS score of 9.6 — is used for persistence outside of the sandbox, installation of backdoors , and permanent modification of the host system configuration.

The vulnerability that worries researchers the most

Among the four vulnerabilities, CVE-2026-44118 is considered the most concerning by design. The issue arises because OpenClaw trusts a client-controlled flag called “senderIsOwner” without properly verifying the authentication session.

Simply put, any non-owner loopback client could falsely present itself as the owner of the runtime and gain access to critical functions such as configuration management, cron scheduling, and control of the execution environment.

The implemented fix completely changes the authentication logic, introducing separate owner and non-owner authentication tokens, while ownership information is now generated exclusively from the auth token and not from client headers that can be forged.

Claw Chain: OpenClaw vulnerabilities allow complete system compromise

TOCTOU vulnerabilities and sandbox bypass

Of particular interest are the two TOCTOU vulnerabilities — known as “Time-of-Check/Time-of-Use” flaws — which were recorded as CVE-2026-44112 and CVE-2026-44113.

Attacks of this type exploit the time gap between the security check and the actual use of a resource. In the case of OpenClaw, attackers were able to redirect file reads and writes outside the intended root sandbox area, completely bypassing security restrictions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Microsoft: Rejects report of critical Azure Backup vulnerability

CVE -2026-44115, on the other hand, uses shell expansion tokens within heredoc payloads, allowing command execution that would normally be blocked by the runtime environment.

Cyera researchers emphasize that the real danger of Claw Chain lies in the fact that the attacks are carried out using the AI ​​agent's own privileges. Essentially, the attacker turns the agent into "digital hands" within the user's environment.

The growing security crisis surrounding OpenClaw

This is not the first time OpenClaw has been targeted by security researchers. In January, a critical RCE vulnerability, CVE-2026-25253, was disclosed, which allowed malicious websites to silently connect to the local agent server via unauthenticated WebSockets.

Meanwhile, a Koi Security of the ClawHub marketplace revealed 341 malicious “skills” among 2,857 available apps. The attacks included credential theft, reverse shells, and cryptomining hijacks.

Claw Chain: OpenClaw vulnerabilities allow complete system compromise

Nvidia attempted to address some of the issues through NemoClaw , an enterprise-grade security platform developed in partnership with Cisco, CrowdStrike, Google, and Microsoft Security . However, NemoClaw operates primarily at the infrastructure orchestration level rather than application sandboxing, meaning that the Claw Chain vulnerabilities were affecting even hardened deployments before the patches were released.

See also: WordPress: Hackers exploit Burst Statistics vulnerability

The big problem of the era of AI agents

The Claw Chain case highlights a much broader issue that is beginning to seriously concern the artificial intelligence industry: AI agents now have access to files, API keys, credentials, cloud infrastructure and corporate data.

When such an agent is compromised, the consequences are practically the same as a complete breach of the user themselves or even the entire organization.

Traditional perimeter security was designed for human users, not autonomous software executing instructions from external sources in real time. Claw Chain may be the incident that forces the industry to finally treat the security of AI agents with the same seriousness that operating systems and cloud infrastructures are treated today.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS