Race Condition in OpenClaw Affecting Microsoft Teams Functionality
CVE-2026-62212

5.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62212?

OpenClaw versions prior to 2026.5.28 are susceptible to a race condition in the safeFetch DNS rebinding check associated with Microsoft Teams. This vulnerability allows lower-trust callers to potentially exploit a timing gap between DNS validation and subsequent action execution. If the affected feature is enabled, attackers may gain unauthorized access by taking advantage of improperly configured security measures. The impact of this vulnerability largely depends on the configurations set by operators and whether inputs classified as lower-trust can navigate to the vulnerable code path.

Affected Version(s)

OpenClaw 0 < 2026.5.28

OpenClaw 2026.5.28

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chinmohan Nayak (@nayakchinmohan)
.