OpenClaw Missing Authorization Vulnerability in MS Teams Message Actions

Vulnerability

A missing authorization vulnerability has been identified in OpenClaw versions 2026.4.12-beta.1 prior to 2026.6.6. This vulnerability exists in the MS Teams message actions feature, where a lower-trust caller or a configured input path can perform actions that should have required stronger authorization or policy checks. The practical impact of this vulnerability depends on the operator's configuration and whether lower-trust input can access the affected path.

Impact

Exploitation of this vulnerability could allow unauthorized actions to be performed in the MS Teams message actions feature, bypassing necessary authorization checks. This could lead to unauthorized changes or actions being taken on behalf of the user.

Remediation

Users are advised to upgrade to OpenClaw version 2026.6.6 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it when not needed.

Added: Jul 17, 2026, 3:33 AM
Updated: Jul 17, 2026, 3:33 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.6
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.