Authorization Bypass Vulnerability in OpenClaw MS Teams by OpenClaw
CVE-2026-62224

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62224?

OpenClaw MS Teams prior to version 2026.5.12 contains an authorization bypass vulnerability that arises from the improper handling of mutable display names within the allowFrom feature. Attackers with limited trust can exploit this weakness to execute actions that necessitate heightened authorization levels, potentially compromising the integrity of user permissions and data security.

Affected Version(s)

msteams 0 < 2026.5.12

msteams 2026.5.12

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gracia-gu
PhilipPhil
.