Executive brief
OpenClaw MS Teams, a library used for integrating Microsoft Teams functionality, contains a security flaw in its 'allowFrom' authorization feature. The system incorrectly identifies users based on their display names, which can be changed by the users themselves, rather than using permanent, unique identifiers. This allows a user with low-level access to impersonate a more privileged user and perform unauthorized actions within the application.
Technical details
An authorization bypass vulnerability exists in OpenClaw MS Teams (npm package @openclaw/msteams) prior to version 2026.5.12. The root cause is an incorrect authorization check (CWE-863) in the 'allowFrom' feature, which relies on mutable display names for identity verification rather than immutable identifiers. A remote attacker with low-privileged access can exploit this by spoofing a trusted display name (CWE-290) to bypass security policies and perform actions requiring higher authorization levels. The vulnerability is reachable over the network if the affected feature is enabled and exposed to lower-trust inputs. A patch is available in version 2026.5.12.
Affected products
- OpenClaw msteams < 2026.5.12
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: CVE published to NVD