Cloud providers began rapidly shipping OpenClaw-as-a-service deployments despite warnings that the AI agent platform is “demonstrably insecure.” OpenClaw is designed to act on users’ behalf across online services (e.g., email and calendars) by taking user credentials and executing instructions via messaging apps such as Telegram or WhatsApp; this model increases blast radius if the platform is compromised. Tencent Cloud, DigitalOcean, and Alibaba Cloud published quick-deploy options (including one-click installers and low-cost small-server templates), effectively lowering the barrier to running OpenClaw in hosted environments.
Separately, CVE-2026-24763 describes an authenticated command injection condition tied to OpenClaw’s Docker execution behavior via manipulation of the PATH environment variable, indicating a concrete exploitation avenue beyond general “insecure by design” concerns. In combination, the rapid commoditization of hosted OpenClaw deployments and the presence of a command-injection class vulnerability heighten the likelihood of real-world abuse, particularly where OpenClaw instances are granted broad credentials and automation permissions.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Trend Micro released research examining the security implications of OpenClaw and agentic assistants, adding industry analysis to concerns around the platform's risk profile. The publication marks a further technical and security-focused response to OpenClaw adoption.
Gartner issued strong guidance warning that OpenClaw poses unacceptable cybersecurity risk because of issues such as plaintext credential storage and lack of authentication by default. The firm advised enterprises to block OpenClaw traffic and downloads or restrict it to isolated nonproduction environments with disposable credentials.
Multiple providers, including Tencent Cloud, DigitalOcean, and Alibaba Cloud, introduced OpenClaw deployment options or hosted-style installation offerings. These services made it easier for users to deploy the AI agent platform in the cloud.
A CVE entry was published for CVE-2026-24763, describing an authenticated command injection issue in OpenClaw Docker execution via the PATH environment variable. The reference also notes the related repository had been linked to multiple CVEs.
The repository described as "Multi-AI documentation for OpenClaw" was created, according to the metadata shown in the reference. This is the earliest concrete event tied to the CVE-related material.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcego.theregister.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.