PT-2026-23556 · Openclaw+1 · Openclaw+1

Yueyuel

·

Published

2026-02-02

·

Updated

2026-03-06

·

CVE-2026-28481

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.1
Description The software contains an information disclosure issue in the MS Teams attachment downloader (optional extension must be enabled). When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, potentially leading to token theft. The default download allowlist uses suffix matching, and a message referencing an untrusted but allowlisted host could cause the bearer token to be sent to the incorrect location.
Recommendations Upgrade to OpenClaw version 2026.2.1 or later. If the MS Teams extension is not needed, disable it. If upgrading is not possible, ensure the auth host allowlist is strict, including only Microsoft-owned endpoints that require authentication, and avoid wildcard or broad suffix entries.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-06333
CVE-2026-28481
GHSA-7VWX-582J-J332

Affected Products

Ms Teams
Openclaw