CVE-2026-28446

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

11 Mar 2026, 14:16

Type Values Removed Values Added
CWE CWE-303

10 Mar 2026, 20:00

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
CWE NVD-CWE-noinfo
References () https://github.com/openclaw/openclaw/commit/f8dfd034f5d9235c5485f492a9e4ccc114e97fdb - () https://github.com/openclaw/openclaw/commit/f8dfd034f5d9235c5485f492a9e4ccc114e97fdb - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-4rj2-gpmh-qq5x - () https://github.com/openclaw/openclaw/security/advisories/GHSA-4rj2-gpmh-qq5x - Exploit, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-inbound-allowlist-policy-bypass-in-voice-call-extension-via-empty-caller-id - () https://www.vulncheck.com/advisories/openclaw-inbound-allowlist-policy-bypass-in-voice-call-extension-via-empty-caller-id - Third Party Advisory
First Time Openclaw openclaw
Openclaw

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Las versiones de OpenClaw anteriores a la 2026.2.1 con la extensión de llamada de voz instalada y habilitada contienen una vulnerabilidad de omisión de autenticación en la validación de la política de lista de permitidos de entrada que acepta identificadores de llamadas vacíos y utiliza la coincidencia basada en sufijos en lugar de la igualdad estricta. Los atacantes remotos pueden omitir los controles de acceso de entrada realizando llamadas con identificadores de llamadas faltantes o números que terminan con dígitos en la lista de permitidos para alcanzar al agente de llamada de voz y ejecutar herramientas.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.4
CWE CWE-303

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-11 14:16


NVD link : CVE-2026-28446

Mitre link : CVE-2026-28446

CVE.ORG link : CVE-2026-28446


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
NVD-CWE-noinfo CWE-303

Incorrect Implementation of Authentication Algorithm