Junglewise Threat Intelligence

CVE-2026-62224: OpenClaw MS Teams authorization bypass in allowFrom feature

CVE-2026-62224 · Severity: medium · CVSS 5.4 · Published 2026-07-17

Technologies: Openclaw Msteams. Vendors: Openclaw.

Executive brief

OpenClaw MS Teams, a library used for integrating Microsoft Teams functionality, contains a security flaw in its 'allowFrom' authorization feature. The system incorrectly identifies users based on their display names, which can be changed by the users themselves, rather than using permanent, unique identifiers. This allows a user with low-level access to impersonate a more privileged user and perform unauthorized actions within the application.

Technical details

An authorization bypass vulnerability exists in OpenClaw MS Teams (npm package @openclaw/msteams) prior to version 2026.5.12. The root cause is an incorrect authorization check (CWE-863) in the 'allowFrom' feature, which relies on mutable display names for identity verification rather than immutable identifiers. A remote attacker with low-privileged access can exploit this by spoofing a trusted display name (CWE-290) to bypass security policies and perform actions requiring higher authorization levels. The vulnerability is reachable over the network if the affected feature is enabled and exposed to lower-trust inputs. A patch is available in version 2026.5.12.

Affected products

  • OpenClaw msteams < 2026.5.12

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats