CVE-2026-62213 Details
Description
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
A token leakage vulnerability has been identified in OpenClaw versions prior to 2026.5.27. This vulnerability occurs in outbound requests to Microsoft Teams, where lower-trust callers can expose Bot Framework tokens. Attackers may access configured input paths to retrieve credentials that should remain within a trusted boundary.
Users are advised to upgrade to OpenClaw version 2026.5.27 or later. Before upgrading, restrict the affected feature to trusted operators or disable it if not needed. As a general hardening measure, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-v54h-q2vx-vgg4 | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-token-leakage-via-ms-teams-outbound-requests | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.5.27 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | Initial Analysis | [email protected] |
| Jul 17, 2026 | New CVE Received | [email protected] |