Improper Input Validation in OpenClaw Bot Framework by OpenClaw
CVE-2026-62214

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62214?

The OpenClaw Bot Framework is susceptible to an improper input validation flaw in versions prior to 2026.5.28. This vulnerability permits lower-trust callers to potentially expose sensitive bot tokens and credentials due to inadequate validation of serviceUrl parameters. Malicious actors can inject harmful serviceUrl values via configured input paths, thereby gaining unauthorized access to confidential authentication data outside of established security boundaries. It is crucial for users to update to the latest version to mitigate these risks.

Affected Version(s)

msteams 0 < 2026.5.28

msteams 2026.5.28

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lewis (@lewiswigmore)
.