Authorization Bypass in OpenClaw's MS Teams Message Actions Feature
CVE-2026-62205
6MEDIUM
What is CVE-2026-62205?
The OpenClaw application contains a missing authorization vulnerability in the MS Teams message actions feature. This issue allows a lower-trust caller to perform actions without the necessary authorization checks, depending on the operator's configuration and the input path's accessibility. The vulnerability impacts versions prior to 2026.6.6, highlighting the importance of proper authorization measures in securing sensitive message actions.
Affected Version(s)
OpenClaw 2026.4.12 < 2026.6.6
OpenClaw 2026.6.6
