#VU125211 Authentication bypass using an alternate path or channel in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to submit unauthorized session feedback.
The vulnerability exists due to incorrect authorization in Microsoft Teams feedback invoke handling when processing feedback invokes from senders. A remote user can send a feedback invoke through an alternate channel to submit unauthorized session feedback.
The issue affects feedback invokes because the sender allowlist checks applied to direct message and group flows were not enforced for this path.