← Retour à la recherche de CVE

CVE-2026-41365

OpenClaw

Description

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.

CVSS 5.4EPSS 0.17700000000000002%Risque 0.55
Voir la source
Publication
2026-04-28 00:16:25
Versions concernées
<2026.3.31
Type
Core software
Dernière modification
2026-07-24 21:10:00
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N