CVE-2026-41375

MEDIUM WAF: Low
CVSS 6.5 Published: 2026-04-28
CWE-863

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication restrictions to arm or disarm phone channels without proper administrative privileges.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
openclawopenclawup to 2026.3.28

References

Back to CVE Database