Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
ID: 910f2d0e-d804-57e0-b32d-4a037636bdb4
STIX ID: report--910f2d0e-d804-57e0-b32d-4a037636bdb4
Feed Name: The Hacker News
Threat Score
## Executive Summary Cyera disclosed four vulnerabilities in OpenClaw/OpenShell—dubbed "Claw Chain"—that together allow an attacker with initial code execution inside the sandbox to read sensitive files, elevate privileges to owner-level, and plant persistent backdoors by abusing TOCTOU races, improper access control, and input validation gaps; the flaws (CVEs 2026-44112/44113/44115/44118) are fixed in OpenClaw 2026.4.22 and users are advised to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
