CVE-2026-34509: OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration
Published Mar 31, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
OpenClaw OpenClaw Microsoft Teams plugin<2026.3.8
Event History
Mar 31, 2026
CVE Published
via MITRE·11:17 AM
Rejected
via MITRE·11:17 AM
Data Sourced
via NVD·12:16 PM
Description
Apr 1, 2026
Rejected
via MITRE·01:50 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-34509?
CVE-2026-34509 has a moderate severity level due to its potential for unauthorized access.
2
How do I fix CVE-2026-34509?
To fix CVE-2026-34509, update the OpenClaw Microsoft Teams plugin to version 2026.3.8 or later.
3
What type of vulnerability is CVE-2026-34509?
CVE-2026-34509 is classified as a sender allowlist bypass vulnerability.
4
Which versions are affected by CVE-2026-34509?
CVE-2026-34509 affects all versions of OpenClaw Microsoft Teams plugin prior to 2026.3.8.
5
What can an attacker do with CVE-2026-34509?
An attacker exploiting CVE-2026-34509 can bypass authorization checks and potentially send unauthorized messages.