CVE-2026-41375
MEDIUM6.5CVSS v3
—CVSS v2
0.33%
EPSS (exploit probability)
CWE-863CWE
Description
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication restrictions to arm or disarm phone channels without proper administrative privileges.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.