The flaw is in the generic channel-tool path, which does not preserve the originating sender's owner status when the request reaches the WhatsApp login tool. As a result, the owner-only control is not applied correctly, and an admitted non-owner sender able to steer the tool can request a forced login for a configured account. The tool can return a new QR code, disconnecting or replacing the Gateway's WhatsApp account; completing an unauthorized relink additionally requires the attacker to scan that QR code with another phone. The confirmed preconditions are an admitted sender and the ability to steer the tool; the public sources do not specify the exact request format or internal authorization check.