CVE-2026-34506
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.
Vendor
Product
CWE
Yayın Tarihi
2026-03-31 12:16:30
Güncelleme
2026-04-01 19:27:12
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-