Junglewise Threat Intelligence

CVE-2026-34506: OpenClaw Microsoft Teams plugin sender allowlist bypass

CVE-2026-34506 · Severity: medium · CVSS 4.3 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing communications, contains a security flaw in its Microsoft Teams integration. This vulnerability allows unauthorized users within a Teams channel to bypass security filters and trigger automated replies or actions that should have been restricted to specific approved senders. This could lead to unauthorized interaction with internal systems or the exposure of information through automated bot responses.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the OpenClaw Microsoft Teams plugin due to improper handling of the 'groupAllowFrom' parameter. When a team or channel route allowlist is configured but the 'groupAllowFrom' parameter is left empty, the message handler incorrectly synthesizes a wildcard authorization. This allows any authenticated user within the matched Teams channel to bypass the intended 'groupPolicy: allowlist' restriction and trigger replies. The vulnerability is reachable over the network by any user with basic access to the affected Teams channel. A fix is available in version 2026.3.8.

Affected products

  • OpenClaw OpenClaw < 2026.3.8

Timeline

  • 2026-03-09: patched: Version 2026.3.8 released
  • 2026-03-11: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD publication date

References

Related threats