CVE-2026-41375

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication restrictions to arm or disarm phone channels without proper administrative privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

01 May 2026, 15:47

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/aa66ae1fc797d3298cc409ed2c5da69a89950a45 - () https://github.com/openclaw/openclaw/commit/aa66ae1fc797d3298cc409ed2c5da69a89950a45 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-h2v7-xc88-xx8c - () https://github.com/openclaw/openclaw/security/advisories/GHSA-h2v7-xc88-xx8c - Patch, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-phone-arm-and-phone-disarm-endpoints - () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-phone-arm-and-phone-disarm-endpoints - Third Party Advisory
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

28 Apr 2026, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 19:37

Updated : 2026-05-01 15:47


NVD link : CVE-2026-41375

Mitre link : CVE-2026-41375

CVE.ORG link : CVE-2026-41375


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-863

Incorrect Authorization