The images in this article were generated with artificial intelligence. How we publish
Cybersecurity researchers have revealed a campaign of crashes focused on OpenClaw that, together, allow from information theft to the escalation of privileges and the installation of persistent back doors. Cyera called this set "Claw Chain": four vulnerabilities that, exploited in sequence, allow an attacker to enter the agent's sandbox, extract secrets, supplant the agent's owner and finally modify the configuration to stay within the environment.
The identified failures include two type-race conditions TOCTOU which can be written or read outside the planned assembly tree (CVE-2026-44112 and CVE-2026-44113), an incomplete validation of inputs that can be avoided by means of shell expansions in heirs (CVE-2026-44115) and a defective access control that trusts a customer-controlled header called senderIsOwner, which allows non-owner customers to scale their privileges (CVE-2026-44118). Each has a serious impact separately, but the real risk comes from the chain: malicious code achieves execution in the sandbox, extracts credentials and sensitive files, gets tokens from "owner" and finally plant mechanisms of persistence and backdoors.

That an opponent uses the agent itself to move within the environment makes the activity seem legitimate in the face of traditional controls: calls, file access and configuration changes benefit from the confidence already given to the agent, which Expands the damage radius and complicates detection. It is therefore essential to address both technical mediation and operational hygiene to reduce the exposure window and potential impact.
OpenClaw published corrections and mitigations in version 2026.4.22 after the responsible disclosure; the accredited discoverer is Vladimir Tokarev. To understand technically the categories of failure in play, it is appropriate to review public resources on career conditions and the validation of entries, for example the MITRE tab on TOCTOU and CWE-367 https: / / cwe.mitre.org / data / definitions / 367.html and Cyera's notes on the finding and classification of the threat https: / / www.cyera.com.
If you manage instances with OpenClaw, the immediate priority is to update to the parched version. In addition to updating, acts on several fronts: revoke and reissue credentials and tokens that may have been exposed, restrict the installation of plugins or external integrations until their integrity is verified, and apply segmentation controls to limit what resources the agents can reach. Check logs and telemetry in search of atypical behavior of the agent - mass readings of sensitive files, scriptures out of permitted routes or changes in programmed tasks - because the chain sought by the attacker imitates legitimate operations.

From the perspective of development and architecture, there are clear lessons: do not trust customer-controlled flags for authorization decisions; it derives the status of owner from authenticated tokens and server contexts, as those responsible have already corrected when issuing separate tokens for owner and non-owner. Avoid TOCTOU with atomic operations, file blocking or verifications that do not depend on unsafe time windows, and sanitize and restrict any shell expansion in complex inputs such as heirs.
For detection and response, it incorporates controls that not only look for signatures, but also abnormal patterns of behavior of the agent: sudden lifting of privileges, access to secrets outside the intended scope, or frequent changes in the runtime configuration. Complete with EDR / EDR-like, file integrity monitoring and least privileged policies in the agent's runtime. If you suspect commitment, you carry out a containment that includes isolating the agent, removing forensic devices and restoring them from good known images after the rotation of secrets.
Claw Chain is a reminder that management and automation agents are valuable objectives: they act with privileges and their normal behavior can hide a holding. It updates, audits and restricts, and considers this case as an example to strengthen the validation of inputs and the strict separation of tokens and responsibilities in any agent-based architecture.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...