PT-2026-31965 · Openclaw+1 · Openclaw+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
Microsoft Teams feedback invokes previously bypassed sender authorization, potentially allowing unauthorized senders to record session feedback or trigger reflection. The issue stemmed from a bypass of sender allowlist checks via feedback invoke endpoints. A commit,
c5415a474bb085404c20f8b312e436997977b1ea, implemented DM and group authorization checks to address this.Recommendations
Update to version 2026.3.25 or later.
Exploit
Fix
Incorrect Authorization
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teams
Openclaw