PT-2026-31965 · Openclaw+1 · Openclaw+1
Peng Zhou
·
Published
2026-03-29
·
Updated
2026-04-10
·
CVE-2026-35654
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
Microsoft Teams feedback invokes previously bypassed sender authorization, potentially allowing unauthorized senders to record session feedback or trigger reflection. The issue stemmed from a bypass of sender allowlist checks via feedback invoke endpoints. A commit,
c5415a474bb085404c20f8b312e436997977b1ea, implemented DM and group authorization checks to address this.Recommendations
Update to version 2026.3.25 or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teams
Openclaw