CVE-2026-41365: OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History

Published Apr 27, 2026
·
Updated

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.

Affected Software

2 affected components
OpenClaw OpenClaw<2026.3.31
OpenClaw Openclaw Node.js<2026.3.31

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.3.31
  2. Compensating control

    Ensure MS Teams thread history fetched via Graph API is not processed in a way that allows sender allowlist filtering to be bypassed (apply the fix for OpenClaw < 2026.3.31, since the bypass affects thread history retrieval).

Event History

Apr 27, 2026
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
DescriptionSeverityWeakness
Apr 28, 2026
Data Sourced
via NVD·12:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-41365?

CVE-2026-41365 is classified as a high severity vulnerability due to its ability to bypass sender allowlists.

2

How do I fix CVE-2026-41365?

To fix CVE-2026-41365, update OpenClaw to version 2026.3.31 or later.

3

Who is affected by CVE-2026-41365?

CVE-2026-41365 affects all versions of OpenClaw prior to 2026.3.31.

4

What type of vulnerability is CVE-2026-41365?

CVE-2026-41365 is a sender allowlist bypass vulnerability in the MS Teams thread history accessed via Graph API.

5

Can CVE-2026-41365 lead to data exposure?

Yes, CVE-2026-41365 allows attackers to retrieve messages that should have been restricted, potentially leading to unauthorized data exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203