PT-2026-35553 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-27

·

Updated

2026-04-28

·

CVE-2026-41365

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-41365

Affected Products

Openclaw