Beveiligingsadvies

CVE-2026-41365

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-27 23:24:28
Laatst bijgewerkt 2026-04-28 13:55:22
Toegewezen door VulnCheck
CVSS-score 5.4
Status PUBLISHED

Beschrijving

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.