
CVE-2026-34506 OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorizat… https://www.cve.org/CVERecord?id=CVE-2026-34506
Post summary
The CVE-2026-34506 disclosure details a sender allowlist bypass in OpenClaw’s Microsoft Teams plugin for versions prior to 2026.3.8, enabling unauthorized senders to circumvent intended authorization checks.
