VYPR
Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026

OpenClaw MS Teams < 2026.5.12 Authorization Bypass

CVE-2026-62224

Description

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.