Impact
OpenClaw 2026.4.12-beta.1 through versions before 2026.6.6 contain a missing authorization vulnerability in the MS Teams message actions feature, allowing callers with lower trust or configured input paths to execute actions that should be protected by a stronger authorization or policy check. The flaw is a classic Authorization Control weakness (CWE‑862). An attacker who can reach the vulnerable path could perform privileged operations, potentially compromising confidentiality and integrity depending on the operator’s configuration and the extent of lower‑trust input that can trigger the actions.
Affected Systems
The vulnerability affects OpenClaw OpenClaw products from version 2026.4.12-beta.1 up to, but not including, 2026.6.6. No other vendor products are listed as affected.
Risk and Exploitability
The CVSS score of 6 indicates moderate risk, while the EPSS score of less than 1% shows that the exploit probability is currently low. Because the issue is not listed in the CISA KEV catalog, there is no evidence of widespread active exploitation. The likely attack vector involves an exposed MS Teams message actions endpoint that can be triggered by a lower‑trust client; an attacker would need to provide input that reaches the vulnerable path to exploit the missing authorization. Given the configuration‑dependent nature of the impact, the real world risk may vary from minimal to significant if lower‑trust input can reach the action handler.
OpenCVE Enrichment