CVE-2026-43572

Source
https://cve.org/CVERecord?id=CVE-2026-43572
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43572.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43572
Aliases
Published
2026-05-05T11:25:12Z
Modified
2026-08-12T03:51:18Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler
Details

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, allowing unauthorized access to Teams SSO signin functionality.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43572.json"
}
References

Affected packages

Git / github.com/openclaw/openclaw

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
    "extracted_events": [
        {
            "introduced": "2026.4.10"
        },
        {
            "fixed": "2026.4.14"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v2026.*
v2026.4.10
v2026.4.11
v2026.4.11-beta.1
v2026.4.12
v2026.4.12-beta.1
v2026.4.14-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43572.json"