Junglewise Threat Intelligence

OpenClaw MS Teams sender allowlist bypass in plugin

Severity: low · CVSS 3.1 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a messaging and collaboration tool that integrates with Microsoft Teams. The vulnerability allows unauthorized senders to bypass authentication checks in the Teams plugin when a route allowlist is configured but the sender allowlist is empty, potentially enabling attackers to trigger replies in restricted Teams channels without proper authorization.

Technical details

The vulnerability is an authentication bypass (CWE-863/CWE-289) in OpenClaw's Microsoft Teams plugin. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler incorrectly synthesizes wildcard sender authorization, allowing any sender within the matched team/channel to bypass the intended groupPolicy allowlist check. The vulnerability requires the specific misconfiguration of route allowlist with empty sender allowlist, and affects versions prior to 2026.3.8. A fix was released in version 2026.3.8, committed on commit 88aee9161e0e6d32e810a25711e32a808a1777b2.

Affected products

  • OpenClaw OpenClaw before 2026.3.8

Timeline

  • 2026-03-31: disclosed
  • 2026-03-08: patched

References

Related threats