Owner context spoofing privilege escalation in OpenClaw loopback MCP
CVE-2026-44118 is an improper access control / identity spoofing flaw in OpenClaw affecting versions before 2026.4.22. In the loopback MCP runtime, OpenClaw derived owner context from spoofable, server-issued bearer-token-associated request header metadata rather than binding owner status to the authenticated session. Specifically, OpenClaw trusted a client-controlled ownership indicator (described in reporting as senderIsOwner / sender-owner header metadata) without cross-referencing it against the bearer token that authenticated the request. As a result, a non-owner loopback client with a valid authentication token could manipulate the ownership metadata and be treated as the owner, bypassing owner-gated operations.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OpenClaw privilege escalation vulnerability that lets a local process with a valid token gain owner-level control because the platform trusted a client-controlled ownership flag without proper session verification.
An OpenClaw privilege escalation flaw that allows a local process with a valid token to gain owner-level control by abusing improper trust in a client-controlled ownership flag.
A high-severity OpenClaw vulnerability in the Claw Chain set that can be chained with other flaws to leak secrets and bypass identity checks for administrator access.
A high-severity privilege escalation vulnerability in OpenClaw caused by trusting a client-controlled ownership flag, allowing a local process with a valid bearer token to gain owner-level control.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.