logo

Claw Chain: Cyera Research Unveil Four Chainable Vulnerabilities in OpenClaw

ID: e06a2964-64c9-5cc0-b664-e17d8545af92

STIX ID: report--e06a2964-64c9-5cc0-b664-e17d8545af92

Feed Name: Cyera Blogs

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

Cyera disclosed four critical/severe vulnerabilities in OpenClaw agents (CVE-2026-44112, CVE-2026-44115, CVE-2026-44118, CVE-2026-44113) that enable sandbox read/write escapes, environment-variable/secret disclosure, and privilege escalation; these can be chained from a single malicious plugin or prompt injection to exfiltrate secrets, escalate to owner privileges, and achieve persistence. The flaws were patched April 23, 2026, but large numbers of publicly reachable instances increase the attack surface and urgency for patching, secret rotation, and network/hardening controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.