PipeRoll - Agent Incident Registry

PIR-2026-0042

Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+ CVE-2026-25253 one-click RCE)
Cite as: PipeRoll PIR-2026-0042, Mass exposure of misconfigured OpenClaw instances leaking agent… (2026-01) - https://piperoll.org/pir/2026-0042

PIR-2026-0042 - Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+ CVE-2026-25253 one-click RCE)

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Independence: good - scan data, vendor patch, and multi-firm coverage are mutually independent. - confidence: high on exposure scale, CVE details, and timeline (21,639 figure verified against Censys-derived reporting); low on realized harm - how many exposed instances were actually plundered is undocumented (the weakest link)