CVE-2026-44118Disclosure(openclaw / openclaw)

LOWCVSS 8.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-05-15); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline9 mentions / 7d
01223Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-15: 3Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-25: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-09-11: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 1Technical Details · 2026-09-11: 105-0605-0705-1505-1705-1805-2509-11
Signal classification3 categories
Disclosure
777.8%
General
111.1%
Patch
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
General1
2026-05-071
Disclosure1
2026-05-153
Disclosure3
2026-05-171
Patch1
2026-05-181
Disclosure1
2026-05-251
Disclosure1
2026-09-111
Disclosure1
Full discourse9 posts
  • The Hacker News@TheHackersNews
    Patch

    🚨 Claw Chain turns your AI agent against you: No credentials needed. CVE-2026-44118 spoofs the senderIsOwner flag → attacker gains owner control. Then chains TOCTOU sandbox escapes + heredoc tricks for data theft → full persistence. Update OpenClaw to 2026.4.22 NOW.

    Post summary

    A CVE-2026-44118 flaw allows attackers to spoof ownership and achieve persistence via sandbox escapes, and a patch (OpenClaw 2026.4.22) is now available to mitigate the issue.

    63921333432.1K
    1.9M followersView on X
  • Ryx@PadhiyarRushi
    Disclosure

    OpenClaw “Claw Chain” is a clean example of AI-agent runtime becoming the attacker’s execution layer. Four bugs: • TOCTOU filesystem write escape (CVE-2026-44112, CVSS 9.6) • Env-var disclosure • MCP loopback owner-flag spoof (CVE-2026-44118) • Read-side TOCTOU Chain them and a sandbox foothold turns into credential theft + persistent host control. Patched in 2026.4.22, but the exposure window was large. https://www.cyera.com/research/four-new-openclaw-vulnerabilities-when-ai-agents-become-the-attackers-execution-layer #AISecurity #AgentSecurity #Cybersecurity #Infosec #Trending #AI #Claude #GPT

    Post summary

    The post discloses four new OpenClaw vulnerabilities with technical details and a patch date, but offers no evidence of active exploitation or explicit exploit code.

    00031280
    954 followersView on X
  • yottajunaid@yottajunaid
    Disclosure

    @TheHackersNews CVE-2026-44118 is the scariest—it tricks the agent by spoofing "senderIsOwner" to take full control. No credentials needed. It's like a master key. Patch to 2026.4.22 now.

    Post summary

    The tweet announces CVE-2026-44118, explains it tricks the agent by spoofing ownership to gain full control without credentials, and urges users to apply patch 2026.4.22.

    01010211
    12 followersView on X
  • ⚡🛡️ Evan Pappas@Hevalon
    Disclosure

    OpenClaw CVE-2026-44118, May 2026: the runtime trusts a client-controlled senderIsOwner flag. The agent self-attests to ownership; the runtime believes it. Whatever the user actually authorised stops mattering. https://t.co/YNH1P1v6QU

    Post summary

    The tweet announces the discovery of OpenClaw CVE‑2026‑44118, where the runtime trusts a client‑controlled flag, allowing unauthorized actions.

    1000097
    1.4K followersView on X
  • HumanAIFusion@humanaifusion
    Disclosure

    (5/6) CVE-2026-44118 | MCP Loopback Privilege Escalation | CVSS 7.8 HIGH OpenClaw: client-supplied senderIsOwner flag trusted without session validation → full owner control. Hermes-Agent: DIRECT architectural match. MCP loopback is core to the stack. Owner = gateway + cron + profiles + kanban. Full instance takeover. P0. Audit now.

    Post summary

    The text announces a new privilege escalation flaw (CVE‑2026‑44118) with CVSS 7.8 High affecting MCP loopback functionality in OpenClaw and Hermes‑Agent, urging immediate audit.

    1000077
    12 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    📍 CVE-2026-44118 الثغره هذي بسبب الثقة العمياء في مدخلات العميل (Never Trust Client Input). الـ API من OpenClaw كان يستقبل قيمة senderIsOwner من العميل مباشرة. إذا المهاجم أرسل true، النظام يصدقه ويعطيه صلاحيات المالك. بدون ما يتحقق من قواعد البيانات أو الجلسة إن العميل فعلاً هو المالك.

    Post summary

    The post announces CVE‑2026‑44118, explaining how OpenClaw’s API blindly trusts a client‑supplied flag to grant ownership privileges, but does not provide PoC, exploit, patch, or exploitation evidence.

    10000151
    49.3K followersView on X
  • Brandon()@brandonbango
    Disclosure

    OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack CVE-2026-44112 (CVSS 9.6 – Critical) CVE-2026-44115 (CVSS 8.8 – High) CVE-2026-44118 (CVSS 7.8 – High) CVE-2026-44113 (CVSS 7.7 – High)

    Post summary

    The post announces OpenClaw Chain vulnerabilities (CVE-2026-44112 through CVE-2026-44113) with high CVSS scores, indicating a disclosure of severe weaknesses but lacking PoC, exploit code, or active exploitation evidence.

    0000076
    121 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44118 OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present the… https://www.cve.org/CVERecord?id=CVE-2026-44118

    Post summary

    CVE‑2026‑44118 allows non‑owner loopback clients in OpenClaw to gain privileged context by exploiting spoofable bearer tokens in request headers, exposing an authentication bypass vulnerability.

    0000078
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44118 Authentication Bypass in OpenClaw Before 2026.4.22 via Spoofable Bearer Tokens https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44118

    Post summary

    The text identifies CVE-2026-44118 as an authentication bypass in OpenClaw, caused by spoofable bearer tokens, but provides no details on PoC, exploit, active use, or patch.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more