Executive brief
OpenClaw, a tool used for managing integrations and automation, contains a security flaw in its Microsoft Teams message actions feature. This vulnerability allows users with low-level access to perform actions they should not be authorized to do, potentially leading to unauthorized data modification or service disruption. The actual impact depends on how the software is configured and whether untrusted users can interact with the Teams integration.
Technical details
A missing authorization vulnerability (CWE-862) exists in OpenClaw's MS Teams message actions feature. The root cause is a failure to perform adequate policy or authorization checks when a caller or input path triggers specific message actions. An authenticated attacker with low privileges can exploit this over the network to perform actions that should require higher authorization levels. This can result in high integrity impact and low availability impact, though it does not directly lead to data confidentiality loss. The issue is resolved in version 2026.6.6.
Affected products
- OpenClaw OpenClaw >= 2026.4.12-beta.1, < 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-16: advisory: VulnCheck advisory published
- 2026-07-17: disclosed: NVD publication date