| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gc9r-867r-j85f | OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 05 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, allowing unauthorized access to Teams SSO signin functionality. | |
| Title | OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-05T14:24:46.058Z
Reserved: 2026-05-01T16:58:23.117Z
Link: CVE-2026-43572
Updated: 2026-05-05T14:24:33.406Z
Status : Undergoing Analysis
Published: 2026-05-05T12:16:21.023
Modified: 2026-05-05T19:32:49.650
Link: CVE-2026-43572
No data.
OpenCVE Enrichment
Updated: 2026-05-05T12:45:24Z
Github GHSA