CyberRota Analysis
AI-GeneratedOpenClaw MS Teams versions prior to 2026.5.12 are susceptible to an authorization bypass vulnerability due to the allowFrom feature's reliance on mutable display names. This flaw enables attackers with lower-trust access to execute actions that typically require higher authorization levels. Organizations using affected versions should prioritize patching to mitigate potential unauthorized access risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.