CVE-2026-34506
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to
CVSS
4.3
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 31 mar 2026 · Última mod.: 24 jul 2026 · CWE-863
0.3%EPSS · 30 días0.3%
2026-08-042026-08-31
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.
- github.comhttps://github.com/openclaw/openclaw/commit/88aee9161e0e6d32e810a25711e32a808a1777b2
- github.comhttps://github.com/openclaw/openclaw/security/advisories/GHSA-g7cr-9h7q-4qxq
- www.vulncheck.comhttps://www.vulncheck.com/advisories/openclaw-sender-allowlist-bypass-in-microsoft-teams-plugin-via-route-allowlist-configuration
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-84355——
———Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)4hCVE-2026-84354——
———Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)4hCVE-2026-84335——
———Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)4hCVE-2026-84334——
———Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)4hCVE-2026-84332——
———Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)4hCVE-2026-84331——
———Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)4h