Access Control Bypass in OpenClaw's Microsoft Teams Integration
CVE-2026-100550
5.3MEDIUM
What is CVE-2026-100550?
OpenClaw, an npm package, contains a vulnerability in its Microsoft Teams integration prior to version 2026.8.1 that allows an access control bypass. When the groupPolicy is configured to allowlist, the absence of a valid access group results in failed group resolution. This oversight permits a Teams member not included in the allowlist to invoke the configured agent, circumventing the administrator's intended group restrictions. The implications of this flaw vary depending on the information and tools accessible to the agent, posing potential security risks. The issue has been promptly addressed in the version 2026.8.1 update.
Affected Version(s)
OpenClaw 0 < 2026.8.1
OpenClaw 2026.8.1
