Executive brief
OpenClaw is an AI automation platform that executes tasks across operating systems and platforms. The `/phone arm` and `/phone disarm` commands fail to properly verify operator permissions when used in external communication channels, allowing unauthorized users to control phone-based security features that should require administrator approval.
Technical details
The vulnerability is an authorization bypass (CWE-285) in OpenClaw's `/phone arm` and `/phone disarm` command handlers. The commands fail to enforce the required `operator.admin` scope check when invoked through external channels, allowing attackers without proper credentials to execute privileged operations. The vulnerability affects all versions through 2026.3.24 and was patched in version 2026.3.28 (commit aa66ae1). The flaw requires network access to invoke the commands but does not require prior authentication or user interaction beyond issuing the malicious commands.
Affected products
- OpenClaw OpenClaw <=2026.3.24; patched in >=2026.3.28
Timeline
- 2026-04-07: disclosed
- 2026-03-27: patched: Fix released in v2026.3.28