CVE-2026-43572: OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler
OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, allowing unauthorized access to Teams SSO signin functionality.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43572?
CVE-2026-43572 is rated as a medium severity vulnerability due to the potential for unauthorized access via missing sender authorization.
How do I fix CVE-2026-43572?
To fix CVE-2026-43572, upgrade OpenClaw to version 2026.4.14 or later, which addresses the missing sender authorization.
What systems are affected by CVE-2026-43572?
CVE-2026-43572 affects OpenClaw versions from 2026.4.10 up to, but not including, 2026.4.14.
What is the impact of CVE-2026-43572?
The impact of CVE-2026-43572 allows attackers to bypass sender allowlist checks, potentially leading to unauthorized actions within Microsoft Teams SSO.
Are there any known exploits for CVE-2026-43572?
As of now, there are no publicly known exploits specifically targeting CVE-2026-43572.