Junglewise Threat Intelligence

CVE-2026-62213: OpenClaw msteams token leakage in MS Teams outbound requests

CVE-2026-62213 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Technologies: Openclaw Msteams. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for integrating with Microsoft Teams, contains a security flaw that can leak sensitive authentication tokens. An attacker with low-level access could exploit this to intercept Bot Framework credentials, potentially allowing them to impersonate the bot or access protected data. This risk is highest when the software is configured to process inputs from untrusted sources.

Technical details

A credential leakage vulnerability exists in the OpenClaw MS Teams integration (specifically the @openclaw/msteams package) due to insufficient protection of credentials during outbound requests. The flaw, classified under CWE-522 and CWE-441, allows an authenticated attacker with low privileges to trigger outbound requests that expose Bot Framework tokens. This occurs when lower-trust callers or specific configured input paths are able to reach the outbound request logic, crossing the intended security boundary. The vulnerability is remediated in version 2026.5.27. Operators are advised to restrict the affected feature to trusted users or disable it until an upgrade is performed.

Affected products

  • OpenClaw msteams < 2026.5.27

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication date
  • 2026-05-27: patched: Date based on version number release sequence

References

Related threats