securityaffairs.com 3/2/2026, 10:37:44 AM · external

ClawJacked flaw in OpenClaw AI lets attackers take admin control

ClawJacked flaw in OpenClaw AI lets attackers take admin control
CyberSIXT Evidence Panel
Primary Source oasis.security
Threat Actor

A high-severity security vulnerability, dubbed 'ClawJacked', was discovered in the OpenClaw AI agent framework, allowing malicious websites to take control of local instances and steal data. The flaw, identified by Oasis Security, enables attackers to brute-force the gateway password or leverage trusted local traffic protocols, gaining admin-level access without any user awareness. OpenClaw quickly released a patch (version 2026.2.26) to address the issue. Developers are advised to update their instances and audit AI tool permissions, emphasizing the need for strict governance around AI agents.

View Primary Source Via securityaffairs.com

Article by CyberSIXT