CVE-2026-28465

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

10 Mar 2026, 18:18

Type Values Removed Values Added
CWE CWE-345

09 Mar 2026, 16:26

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/a749db9820eb6d6224032a5a34223d286d2dcc2f - () https://github.com/openclaw/openclaw/commit/a749db9820eb6d6224032a5a34223d286d2dcc2f - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x - () https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-voice-call-webhook-verification-bypass-via-forwarded-headers - () https://www.vulncheck.com/advisories/openclaw-voice-call-webhook-verification-bypass-via-forwarded-headers - Third Party Advisory
CWE CWE-290
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Las versiones del plugin de llamadas de voz de OpenClaw anteriores a la 2026.2.3 contienen una vulnerabilidad de autenticación impropia en la verificación de webhooks que permite a atacantes remotos eludir la verificación al suministrar encabezados reenviados no confiables. Los atacantes pueden falsificar eventos de webhook manipulando los encabezados Forwarded o X-Forwarded-* en configuraciones de proxy inverso que confían implícitamente en estos encabezados.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.9

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-10 18:18


NVD link : CVE-2026-28465

Mitre link : CVE-2026-28465

CVE.ORG link : CVE-2026-28465


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-290

Authentication Bypass by Spoofing