CVE-2026-41365: OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.31 - Compensating control
Ensure MS Teams thread history fetched via Graph API is not processed in a way that allows sender allowlist filtering to be bypassed (apply the fix for OpenClaw < 2026.3.31, since the bypass affects thread history retrieval).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41365?
CVE-2026-41365 is classified as a high severity vulnerability due to its ability to bypass sender allowlists.
How do I fix CVE-2026-41365?
To fix CVE-2026-41365, update OpenClaw to version 2026.3.31 or later.
Who is affected by CVE-2026-41365?
CVE-2026-41365 affects all versions of OpenClaw prior to 2026.3.31.
What type of vulnerability is CVE-2026-41365?
CVE-2026-41365 is a sender allowlist bypass vulnerability in the MS Teams thread history accessed via Graph API.
Can CVE-2026-41365 lead to data exposure?
Yes, CVE-2026-41365 allows attackers to retrieve messages that should have been restricted, potentially leading to unauthorized data exposure.