PT-2026-29237 · Microsoft+1 · Teams Plugin+1
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.8
Description
The software contains a sender allowlist bypass issue in its Microsoft Teams plugin. This allows unauthorized senders to circumvent authorization checks. Specifically, when a team/channel route allowlist is configured with an empty
groupAllowFrom parameter, the message handler creates wildcard sender authorization. This permits any sender within the matched team/channel to initiate replies in allowlisted Teams routes.Recommendations
Update to version 2026.3.8 or later.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Teams Plugin
Openclaw