Skip to main content
Vulnerability Database/CVE-2026-100550

CVE-2026-100550: OpenClaw Microsoft Teams Auth Bypass

CVE-2026-100550 is an authentication bypass flaw in OpenClaw's Microsoft Teams integration that allows unauthorized users to access protected agents. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100550 Overview

CVE-2026-100550 is an access-control bypass in OpenClaw, distributed as the npm package openclaw, affecting versions before 2026.8.1. The flaw resides in the Microsoft Teams integration. When groupPolicy is configured as allowlist, a missing or unsupported access group produces a denied group-resolution result. The final message-admission check fails to reject that denied result. As a consequence, a Teams member outside the allowlist can still invoke the configured agent. The issue is tracked as a broken authorization weakness [CWE-863] and is fixed in version 2026.8.1.

Critical Impact

Unauthorized Teams members can trigger a restricted agent, exposing any conversations, tools, and data available to that agent despite the administrator's group boundary.

Affected Products

  • OpenClaw npm package openclaw versions prior to 2026.8.1
  • Deployments using the Microsoft Teams integration
  • Configurations where groupPolicy is set to allowlist

Discovery Timeline

  • 2026-09-26 - CVE-2026-100550 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100550

Vulnerability Analysis

The vulnerability affects OpenClaw's authorization pipeline for its Microsoft Teams agent integration. Administrators can constrain access using groupPolicy: allowlist, which should limit agent invocation to members of a configured access group. The resolver that evaluates group membership can return a denied result when the configured group is missing or unsupported. The downstream message-admission check does not treat this denied result as a hard rejection. The gate therefore passes the request through, and the agent executes as if authorization succeeded. This is a classic incorrect-authorization pattern described in CWE-863.

Root Cause

The root cause is a missing failure-closed check between two authorization stages. The group-resolution component returns a tri-state outcome, including a denied state for misconfigured or unsupported groups. The admission layer only enforces the explicit allow path and does not propagate the denied signal into a terminal deny decision. Any administrator misconfiguration therefore collapses the allowlist boundary rather than hardening it.

Attack Vector

Exploitation requires an authenticated Teams user in the tenant where the OpenClaw agent is deployed. The attacker does not need to belong to the allowlisted group. By addressing the agent through the normal Teams interaction surface, the user triggers the broken admission path and causes the agent to process the message. Impact depends on what the agent can access, including connected tools, data sources, and conversation history. See the GitHub Security Advisory GHSA-8938 and the VulnCheck Authentication Bypass Advisory for additional context.

Detection Methods for CVE-2026-100550

Indicators of Compromise

  • Agent invocation events in OpenClaw logs where the requesting Teams user identifier is not a member of the configured allowlist group
  • Group-resolution log entries indicating a denied or unsupported group outcome paired with a subsequent successful admission
  • Unexpected tool or data access by the OpenClaw agent originating from Teams channels outside the intended scope

Detection Strategies

  • Correlate OpenClaw admission logs with Microsoft Teams audit logs to identify agent invocations by users outside the allowlisted group
  • Review configuration drift events that reference groupPolicy or access group identifiers to catch missing or unsupported group references
  • Flag any agent response delivered to a user whose group membership was previously logged as unresolved

Monitoring Recommendations

  • Alert on OpenClaw deployments running versions earlier than 2026.8.1 detected through software inventory scans
  • Monitor Microsoft 365 audit logs for anomalous bot invocation patterns against OpenClaw agent identities
  • Track changes to the OpenClaw configuration file controlling groupPolicy and the referenced access group

How to Mitigate CVE-2026-100550

Immediate Actions Required

  • Upgrade the openclaw npm package to version 2026.8.1 or later across all environments
  • Audit current groupPolicy configurations and verify every referenced access group exists and is supported
  • Review Teams audit logs since the deployment date to identify unauthorized agent invocations

Patch Information

The maintainers fixed the issue in OpenClaw 2026.8.1. The patched release corrects the admission check so that a denied group-resolution result terminates the request. Upgrade using npm install openclaw@2026.8.1 or pin the dependency to >=2026.8.1 in package.json. Full details are documented in GitHub Security Advisory GHSA-8938.

Workarounds

  • Temporarily disable the Microsoft Teams integration until the upgrade is applied
  • Restrict the agent's connected tools and data sources to limit blast radius if invoked by unauthorized users
  • Replace the allowlist policy with a channel-scoped or tenant-scoped Teams app installation that enforces access at the Teams platform layer
bash
# Configuration example: upgrade and verify the installed version
npm install openclaw@2026.8.1
npm ls openclaw

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.