PT-2026-31965 · Openclaw+1 · Openclaw+1

Peng Zhou

·

Published

2026-03-29

·

Updated

2026-04-10

·

CVE-2026-35654

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description Microsoft Teams feedback invokes previously bypassed sender authorization, potentially allowing unauthorized senders to record session feedback or trigger reflection. The issue stemmed from a bypass of sender allowlist checks via feedback invoke endpoints. A commit, c5415a474bb085404c20f8b312e436997977b1ea, implemented DM and group authorization checks to address this.
Recommendations Update to version 2026.3.25 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35654
GHSA-RF6H-5GPW-QRGQ

Affected Products

Teams
Openclaw