CVE-2026-62213: OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.27
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62213?
CVE-2026-62213 has a medium severity rating of 6.
How do I fix CVE-2026-62213?
To fix CVE-2026-62213, upgrade OpenClaw to version 2026.5.27 or later.
What does CVE-2026-62213 affect?
CVE-2026-62213 affects OpenClaw versions prior to 2026.5.27.
What is the risk associated with CVE-2026-62213?
The risk associated with CVE-2026-62213 is rated at 38, indicating a moderate threat level.
How can attackers exploit CVE-2026-62213?
Attackers can exploit CVE-2026-62213 by accessing Bot Framework tokens through lower-trust callers in MS Teams outbound requests.