CVE-2026-34506: OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClaw Microsoft Teams pluginto a version that resolves this vulnerability.Fixed in 2026.3.8 - Configuration
Avoid configuring a team/channel route allowlist with an empty groupAllowFrom parameter; set groupAllowFrom to a non-empty value so the message handler does not synthesize wildcard sender authorization.
OpenClaw Microsoft Teams plugin groupAllowFrom = non-empty
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34506?
The severity of CVE-2026-34506 is classified as high due to its potential to allow unauthorized access.
How do I fix CVE-2026-34506?
To fix CVE-2026-34506, upgrade to OpenClaw version 2026.3.8 or later, which resolves the sender allowlist bypass issue.
What causes the vulnerability in CVE-2026-34506?
CVE-2026-34506 is caused by a flaw in the route allowlist configuration of the Microsoft Teams plugin, allowing unauthorized senders to bypass checks.
Who is affected by CVE-2026-34506?
Users of OpenClaw versions prior to 2026.3.8 that utilize the Microsoft Teams plugin are affected by CVE-2026-34506.
What are the potential impacts of CVE-2026-34506?
The potential impacts of CVE-2026-34506 include unauthorized access to team communications and data, leading to information disclosure.