Unknown · Openclaw Ms Teams · CVE-2026-62224
**Name of the Vulnerable Software and Affected Versions**
OpenClaw MS Teams versions prior to 2026.5.12
**Description**
An authorization bypass exists in the `allowFrom` feature, which binds to mutable display names. This allows attackers with lower-trust access to perform actions that require stronger authorization by exploiting the way the feature handles these mutable names.
**Recommendations**
Update to version 2026.5.12 or later.