{"id":"CVE-2026-34506","title":"OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks","summary":"OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an e…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-863"],"vendor":"openclaw","product":"openclaw","affected":["openclaw < 2026.3.8"],"patched":["openclaw 2026.3.8"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34506","references":[{"url":"https://github.com/openclaw/openclaw/commit/88aee9161e0e6d32e810a25711e32a808a1777b2","label":"disclosure@vulncheck.com"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-g7cr-9h7q-4qxq","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-sender-allowlist-bypass-in-microsoft-teams-plugin-via-route-allowlist-configuration","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00267,"epssPercentile":0.1911,"ingestedAt":"2026-07-24T22:40:25.354Z","slug":"CVE-2026-34506","body":"## Overview\n\nOpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.\n\n## Affected\n\n- `openclaw < 2026.3.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openclaw 2026.3.8`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}