CVE-2026-43572

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, allowing unauthorized access to Teams SSO signin functionality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

07 May 2026, 16:03

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/80b1fa17bfc3f6a668492f0326ea52f48bb89776 - () https://github.com/openclaw/openclaw/commit/80b1fa17bfc3f6a668492f0326ea52f48bb89776 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-gc9r-867r-j85f - () https://github.com/openclaw/openclaw/security/advisories/GHSA-gc9r-867r-j85f - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-missing-sender-authorization-in-microsoft-teams-sso-invoke-handler - () https://www.vulncheck.com/advisories/openclaw-missing-sender-authorization-in-microsoft-teams-sso-invoke-handler - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw

05 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 12:16

Updated : 2026-05-07 16:03


NVD link : CVE-2026-43572

Mitre link : CVE-2026-43572

CVE.ORG link : CVE-2026-43572


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-862

Missing Authorization