PatchSiren cyber security CVE debrief
CVE-2026-100550 OpenClaw CVE debrief
CVE-2026-100550 is a medium-severity vulnerability in the OpenClaw npm package before version 2026.8.1. An access-control bypass issue exists in the Microsoft Teams integration when the groupPolicy is set to allowlist. This could potentially allow unauthorized access to certain agents despite administrative group boundaries. The issue arises when a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check. As a result, a Teams member who is not on the allowlist can still trigger the configured agent, depending on the conversations, tools, and data available to that agent.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw deployments, especially those using the Microsoft Teams integration, should assess their exposure and verify their version of OpenClaw. This includes reviewing the current version and upgrading to 2026.8.1 or later if necessary. Additionally, defenders should review and update Microsoft Teams integration configurations to ensure proper access controls and assess the potential impact of the vulnerability in their
Why it matters
CVE-2026-100550 is a medium-severity vulnerability in OpenClaw that could allow unauthorized access to certain agents. Defenders should prioritize verifying their OpenClaw version and assessing exposure, especially if using the Microsoft Teams integration.
- Potential unauthorized access to certain agents despite administrative group boundaries
- Possible exposure of conversations, tools, and data available to the agent
- Need to verify OpenClaw version and assess exposure
- Potential impact on data integrity and confidentiality
Technical summary
The OpenClaw npm package before version 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group can lead to a denied group-resolution result that is not rejected by the final message-admission check. This allows a Teams member not on the allowlist to trigger the configured agent despite administrative group boundaries.
Defensive priority
Defenders should prioritize verifying their OpenClaw version and assessing exposure, especially if using the Microsoft Teams integration.
Recommended defensive actions
- Verify OpenClaw version and upgrade to 2026.8.1 or later if necessary
- Assess exposure and potential impact of the vulnerability in your environment
- Review and update Microsoft Teams integration configurations to ensure proper access controls
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, additional information from the vendor and other sources may be necessary for a comprehensive understanding. The vulnerability is fixed in version 2026.8.1. OpenClaw deployments, especially those using the Microsoft Teams integration, should verify their version and assess exposure. The CVSS score for this vulnerability is 5.3, indicating a medium severity. The impact depends on the conversations, tools, and data available to the agent. Defenders should review
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100550 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100550
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100550 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100550
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-8938-r7c6-54vq
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-authentication-bypass-via-access-group
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.