CVE-2026-34506 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended auth…
Low CVSS: 2.3

CVE-2026-34506

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-863
Yayın Tarihi
2026-03-31 12:16:30
Güncelleme
2026-04-01 19:27:12
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar