CVE-2026-28481 Details
Description
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft.
A vulnerability allowing information disclosure has been identified in OpenClaw versions through 2026.1.30. This issue resides in the MS Teams attachment downloader, which must be enabled as an optional extension. The vulnerability allows bearer tokens to be leaked to untrusted hosts that are on the suffix-based allowlist. This occurs when the application retries downloads after receiving 401 or 403 responses, inadvertently sending authorization tokens to these allowlisted domains, which could lead to token theft.
Users can upgrade to OpenClaw version 2026.2.1 or later, where this vulnerability has been patched. If upgrading is not possible, the MS Teams extension can be disabled, or the authorization host allowlist can be made stricter by only including Microsoft-owned endpoints that require authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | <= 2026.1.30 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |