Junglewise Threat Intelligence

OpenClaw MS Teams file consent authorization bypass

Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Microsoft Teams integration library used to handle file uploads and consent flows. The vulnerability allows an attacker who obtains a file upload ID to complete or cancel uploads across different conversations without authorization, potentially leading to unwanted file operations or denial of service to victims.

Technical details

The vulnerability is an authorization bypass (CWE-639, CWE-862) in the fileConsent/invoke endpoint used to handle file upload consent. The root cause is that the invoke handler validated uploads by uploadId alone without verifying that the conversation initiating the accept/decline action matches the conversation that created the pending upload. An attacker with a valid uploadId (obtained through disclosure or interception) can trigger cross-conversation upload completion or cancellation. The vulnerability affects all versions up to 2026.2.24 and is patched in 2026.2.25 by enforcing conversation ID binding before consuming pending upload state. No authentication bypass is required—the attack requires network access to the Teams endpoint and a valid uploadId within its TTL.

Affected products

  • OpenClaw openclaw <=2026.2.24

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Fix released in version 2026.2.25
  • 2026-03-03: advisory

References

Related threats