Improper access control in OpenClaw - CVE-2026-41375
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to improper access control in /phone arm and /phone disarm command handling when processing requests for external channels. A remote user can invoke these commands without the required operator.admin scope to bypass authorization checks.
The issue is specific to external channels.