Medium severity5.4NVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
CVE-2026-62224
CVE-2026-62224
Description
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.