PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100550 OpenClaw CVE debrief

CVE-2026-100550 is a medium-severity vulnerability in the OpenClaw npm package before version 2026.8.1. An access-control bypass issue exists in the Microsoft Teams integration when the groupPolicy is set to allowlist. This could potentially allow unauthorized access to certain agents despite administrative group boundaries. The issue arises when a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check. As a result, a Teams member who is not on the allowlist can still trigger the configured agent, depending on the conversations, tools, and data available to that agent.

Vendor
OpenClaw
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for OpenClaw deployments, especially those using the Microsoft Teams integration, should assess their exposure and verify their version of OpenClaw. This includes reviewing the current version and upgrading to 2026.8.1 or later if necessary. Additionally, defenders should review and update Microsoft Teams integration configurations to ensure proper access controls and assess the potential impact of the vulnerability in their

Why it matters

CVE-2026-100550 is a medium-severity vulnerability in OpenClaw that could allow unauthorized access to certain agents. Defenders should prioritize verifying their OpenClaw version and assessing exposure, especially if using the Microsoft Teams integration.

  • Potential unauthorized access to certain agents despite administrative group boundaries
  • Possible exposure of conversations, tools, and data available to the agent
  • Need to verify OpenClaw version and assess exposure
  • Potential impact on data integrity and confidentiality

Technical summary

The OpenClaw npm package before version 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group can lead to a denied group-resolution result that is not rejected by the final message-admission check. This allows a Teams member not on the allowlist to trigger the configured agent despite administrative group boundaries.

Defensive priority

Defenders should prioritize verifying their OpenClaw version and assessing exposure, especially if using the Microsoft Teams integration.

Recommended defensive actions

  • Verify OpenClaw version and upgrade to 2026.8.1 or later if necessary
  • Assess exposure and potential impact of the vulnerability in your environment
  • Review and update Microsoft Teams integration configurations to ensure proper access controls
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, additional information from the vendor and other sources may be necessary for a comprehensive understanding. The vulnerability is fixed in version 2026.8.1. OpenClaw deployments, especially those using the Microsoft Teams integration, should verify their version and assess exposure. The CVSS score for this vulnerability is 5.3, indicating a medium severity. The impact depends on the conversations, tools, and data available to the agent. Defenders should review

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100550 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100550

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100550 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100550

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.