Description
OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.
Published: 2026-07-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw 2026.4.12-beta.1 through versions before 2026.6.6 contain a missing authorization vulnerability in the MS Teams message actions feature, allowing callers with lower trust or configured input paths to execute actions that should be protected by a stronger authorization or policy check. The flaw is a classic Authorization Control weakness (CWE‑862). An attacker who can reach the vulnerable path could perform privileged operations, potentially compromising confidentiality and integrity depending on the operator’s configuration and the extent of lower‑trust input that can trigger the actions.

Affected Systems

The vulnerability affects OpenClaw OpenClaw products from version 2026.4.12-beta.1 up to, but not including, 2026.6.6. No other vendor products are listed as affected.

Risk and Exploitability

The CVSS score of 6 indicates moderate risk, while the EPSS score of less than 1% shows that the exploit probability is currently low. Because the issue is not listed in the CISA KEV catalog, there is no evidence of widespread active exploitation. The likely attack vector involves an exposed MS Teams message actions endpoint that can be triggered by a lower‑trust client; an attacker would need to provide input that reaches the vulnerable path to exploit the missing authorization. Given the configuration‑dependent nature of the impact, the real world risk may vary from minimal to significant if lower‑trust input can reach the action handler.

Generated by OpenCVE AI on July 31, 2026 at 00:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw 2026.6.6 or later to remove the missing authorization flaw.
  • If upgrading is not immediately possible, disable the MS Teams message actions feature in the affected versions.
  • Restrict lower‑trust client access or enforce stricter policy checks on input paths to prevent unauthorized action execution.

Generated by OpenCVE AI on July 31, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.
Title OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-862
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-17T13:02:13.887Z

Reserved: 2026-07-13T16:39:22.250Z

Link: CVE-2026-62205

cve-icon Vulnrichment

Updated: 2026-07-17T13:02:10.085Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses