Cyera Finds Four OpenClaw Flaws, Patch v2026.4.22

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Cyera disclosed four OpenClaw vulnerabilities, dubbed “Claw Chain,” that can be chained for data theft, privilege escalation, and persistence.
- OpenShell has a TOCTOU race condition in its sandbox backend (CVE‑2026‑44112) that lets attackers bypass sandbox restrictions and redirect writes outside the mount root, with CVSS 9.6.
- OpenShell also contains a TOCTOU race condition (CVE‑2026‑44113) that lets attackers bypass sandbox restrictions to read files outside the mount root, scoring CVSS 7.7.
- OpenClaw's allowlist validation can be bypassed (CVE‑2026‑44115) by embedding shell expansion tokens in a heredoc, enabling unapproved command execution, CVSS 8.8.
- OpenClaw trusts a client‑controlled “senderIsOwner” flag (CVE‑2026‑44118), allowing non‑owner loopback clients to impersonate owners and gain privileged control over gateway configuration and execution environment, CVSS 7.8.
- OpenClaw released version 2026.4.22 fixing all four CVEs after responsible disclosure by researcher Vladimir Tokarev.
- Cyera warned that the exploitation chain can appear as normal agent behavior, broadening blast radius and making detection harder.
Why it matters: Attackers gain a full‑stack exploit chain that lets them read secrets, hijack owner privileges, and embed backdoors while appearing as normal agent activity, while defenders must urgently apply the 2026.4.22 patch to close the high‑severity CVEs and restore secure sandbox enforcement.
Ask SkimNews




