Sender Allowlist Bypass Vulnerability in OpenClaw for MS Teams
CVE-2026-41365
5.3MEDIUM
What is CVE-2026-41365?
OpenClaw prior to version 2026.3.31 is vulnerable to a sender allowlist bypass, enabling attackers to access thread history messages from Microsoft Teams through the Graph API. This flaw allows unauthorized users to circumvent established filtering mechanisms intended to restrict message visibility based on sender criteria. This vulnerability poses significant risks related to data exposure, making it critical for users to update to the latest version to ensure their security against these potential threats.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
