Description
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Published: 2026-07-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions prior to 2026.5.27 contain a flaw identified as CWE‑522 that permits lower‑trust callers to trigger outbound Microsoft Teams requests and cause internal Bot Framework tokens to be exposed. Because these tokens authenticate bots to Microsoft services, disclosure could let an attacker impersonate the bot, access protected resources, or compromise downstream systems. The weakness is an unchecked credential exposure that does not require elevated privileges or special configuration beyond the default deployment.

Affected Systems

The affected product is OpenClaw’s Microsoft Teams integration component. All builds released before 2026.5.27 are vulnerable. Users who deploy these versions and expose the outbound Teams API endpoint to external or lower‑trust callers are at risk.

Risk and Exploitability

The CVSS score of 6.0 classifies the flaw as moderate severity. The EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send or trigger an outbound call from a lower‑trust context—such as an unauthenticated or unprivileged user—to the Teams API endpoint that inadvertently exposes the Bot Framework token. No elevated privileges or additional configuration beyond the default deployment is required.

Generated by OpenCVE AI on July 31, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.5.27 or later where the outbound request handling is corrected.
  • Restrict the outbound Microsoft Teams API endpoint so that only trusted callers can invoke it, preventing lower‑trust callers from triggering token exposure.
  • Monitor logs for anomalous outbound token usage and configure alerts on suspicious patterns to detect potential leakage attempts.

Generated by OpenCVE AI on July 31, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Openclaw
Openclaw msteams
Vendors & Products Openclaw
Openclaw msteams

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Title OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Msteams
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-20T23:34:19.682Z

Reserved: 2026-07-13T16:39:22.251Z

Link: CVE-2026-62213

cve-icon Vulnrichment

Updated: 2026-07-20T23:34:15.855Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials