Authentication bypass using an alternate path or channel in OpenClaw - #VU125211

 

Authentication bypass using an alternate path or channel in OpenClaw - #VU125211

Published: April 8, 2026


Vulnerability identifier: #VU125211
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to submit unauthorized session feedback.

The vulnerability exists due to incorrect authorization in Microsoft Teams feedback invoke handling when processing feedback invokes from senders. A remote user can send a feedback invoke through an alternate channel to submit unauthorized session feedback.

The issue affects feedback invokes because the sender allowlist checks applied to direct message and group flows were not enforced for this path.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.


External References

Related Security Bulletins