Authorization Bypass in OpenClaw's MS Teams Message Actions Feature
CVE-2026-62205

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62205?

The OpenClaw application contains a missing authorization vulnerability in the MS Teams message actions feature. This issue allows a lower-trust caller to perform actions without the necessary authorization checks, depending on the operator's configuration and the input path's accessibility. The vulnerability impacts versions prior to 2026.6.6, highlighting the importance of proper authorization measures in securing sensitive message actions.

Affected Version(s)

OpenClaw 2026.4.12 < 2026.6.6

OpenClaw 2026.6.6

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dongyoon (@wwwvwwvwwwwwvwwvw)
.