#VU126429 Missing Authorization in OpenClaw
Published: April 17, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass sender authorization checks.
The vulnerability exists due to improper access control in the Microsoft Teams SSO invoke handler when processing signin invoke requests. A remote user can send a crafted invoke from a disallowed sender to bypass sender authorization checks.
The issue affects SSO signin invoke handling, while normal message handling applies sender allowlist checks.