Authorization Bypass Vulnerability in OpenClaw MS Teams by OpenClaw
CVE-2026-62224
2.3LOW
What is CVE-2026-62224?
OpenClaw MS Teams prior to version 2026.5.12 contains an authorization bypass vulnerability that arises from the improper handling of mutable display names within the allowFrom feature. Attackers with limited trust can exploit this weakness to execute actions that necessitate heightened authorization levels, potentially compromising the integrity of user permissions and data security.
Affected Version(s)
msteams 0 < 2026.5.12
msteams 2026.5.12
