{"id":"CVE-2026-62224","title":"OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names","summary":"OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploi…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-290","CWE-863"],"vendor":"openclaw","product":"msteams","affected":["msteams < 2026.5.12"],"published":"2026-07-17","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:26.640","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62224","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-7w4v-g4m6-j88v","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-ms-teams-authorization-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-17T14:10:07.749014Z"},"epss":0.0026,"epssPercentile":0.162,"ingestedAt":"2026-10-08T16:52:14.702Z","slug":"CVE-2026-62224","body":"## Overview\n\nOpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}