Race Condition in OpenClaw Affecting Microsoft Teams Functionality
CVE-2026-62212
5.1MEDIUM
What is CVE-2026-62212?
OpenClaw versions prior to 2026.5.28 are susceptible to a race condition in the safeFetch DNS rebinding check associated with Microsoft Teams. This vulnerability allows lower-trust callers to potentially exploit a timing gap between DNS validation and subsequent action execution. If the affected feature is enabled, attackers may gain unauthorized access by taking advantage of improperly configured security measures. The impact of this vulnerability largely depends on the configurations set by operators and whether inputs classified as lower-trust can navigate to the vulnerable code path.
Affected Version(s)
OpenClaw 0 < 2026.5.28
OpenClaw 2026.5.28
