CVE-2026-41405

· NIST NVD ↗

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.

HIGH
CVSS severity
7.5
CVSS base score
2026-04-28
Published

CWE codes

CWE-408

Affected products

openclaw:openclaw

Sources