logo

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

ID: 910f2d0e-d804-57e0-b32d-4a037636bdb4

STIX ID: report--910f2d0e-d804-57e0-b32d-4a037636bdb4

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: [email protected] (The Hacker News)

...
...

## Executive Summary Cyera disclosed four vulnerabilities in OpenClaw/OpenShell—dubbed "Claw Chain"—that together allow an attacker with initial code execution inside the sandbox to read sensitive files, elevate privileges to owner-level, and plant persistent backdoors by abusing TOCTOU races, improper access control, and input validation gaps; the flaws (CVEs 2026-44112/44113/44115/44118) are fixed in OpenClaw 2026.4.22 and users are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.