Originally launched as “Clawdbot” in late 2025, OpenClaw connects large language models directly to filesystems, SaaS applications, credentials, and execution environments.
Enterprises have rapidly adopted it for IT automation, customer service pipelines, and operational integrations with platforms like Telegram, Discord, and Microsoft Agent 365. That broad, privileged access makes it an exceptionally high-value target.
Cyera’s research team identified the four previously undisclosed vulnerabilities and disclosed them to OpenClaw maintainers in April 2026. All four have since been patched.
senderIsOwner) without cross-referencing the authenticated session, allowing a local process with a valid bearer token to escalate to owner-level control over gateway configuration, scheduling, and execution management.While each flaw carries its own weight, their combined effect, dubbed “Claw Chain” by Cyera, is far more alarming.
From a single foothold, such as a malicious plugin, prompt injection, or compromised external input, an attacker can chain three vulnerabilities in parallel:
What makes this chain especially dangerous is that the attacker weaponizes the AI agent’s own privileges. Each step mimics normal agent behavior, making detection significantly harder for traditional security controls.
Shodan and ZoomEye scans as of May 2026 reveal approximately 65,000 and 180,000 publicly accessible OpenClaw instances, respectively, totaling roughly 245,000 exposed servers.
Enterprises in financial services, healthcare, and legal sectors face the highest risk, particularly where agent workflows process PII, PHI, or privileged credentials.
Organizations running OpenClaw should treat this as a Priority 1 advisory:
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The post OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack appeared first on Cyber Security News.
Similar to every other high-end GPU on the market, the AMD Radeon 9070 XT graphics…
Best Buy has dropped some great deals on select games for Nintendo Switch and Nintendo…
Forza Horizon 6 has already reached an impressive player count on Steam despite its official…
Forza Horizon 6 finally brings the racing series to Japan. Players can cruise around a…
Car dashcams have their uses. They can come in handy for recording accidents when nobody…
A critical security flaw discovered in Android 16 allows malicious apps to leak a user’s…
This website uses cookies.