Agents
Cyera Discloses 'Claw Chain' — Four Chainable OpenClaw Vulnerabilities Exposing 245,000 Public AI Agent Servers
Cyera Research publicly disclosed four chainable vulnerabilities in OpenClaw on May 15, collectively dubbed 'Claw Chain,' enabling sandbox escape, privilege escalation to owner-level control, and persistent backdoors. CVE-2026-44112 (CVSS 9.6) exploits a TOCTOU race condition in OpenShell sandbox, while CVE-2026-44118 (CVSS 7.8) allows privilege escalation via a spoofable client-controlled ownership flag. Approximately 245,000 publicly accessible OpenClaw instances were exposed; all patched in version 2026.4.22.
↳ Follow the thread