#VU125138 Authentication Bypass by Alternate Name in OpenClaw - CVE-2026-34506
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass sender authorization checks.
The vulnerability exists due to improper access control in the Microsoft Teams plugin message handler when processing messages for a route with a configured team/channel allowlist and an empty groupAllowFrom setting. A remote user can send messages from an unauthorized sender within the matched team/channel to bypass sender authorization checks.
This issue only arises when groupPolicy is set to "allowlist", a route allowlist is configured, and the sender allowlist is empty.