PT-2026-60623 · Microsoft+1 · Ms Teams+1

·

CVE-2026-62213

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.27
Description An issue in MS Teams outbound requests allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that are intended to remain within the trusted boundary.
Recommendations Update to version 2026.5.27.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62213
GHSA-V54H-Q2VX-VGG4

Affected Products

Ms Teams
Openclaw