CVE-2026-29606

OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests when the tunnel.allowNgrokFreeTierLoopbackBypass option is explicitly enabled. An external attacker can send forged requests to the publicly reachable webhook endpoint without a valid X-Twilio-Signature header, resulting in unauthorized webhook event handling and potential request flooding attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

11 Mar 2026, 01:10

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/ff11d8793b90c52f8d84dae3fbb99307da51b5c9 - () https://github.com/openclaw/openclaw/commit/ff11d8793b90c52f8d84dae3fbb99307da51b5c9 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-c37p-4qqg-3p76 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-c37p-4qqg-3p76 - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-webhook-signature-verification-bypass-via-ngrok-loopback-compatibility - () https://www.vulncheck.com/advisories/openclaw-webhook-signature-verification-bypass-via-ngrok-loopback-compatibility - Third Party Advisory
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.14 contienen un bypass de verificación de firma de webhook en la extensión de llamadas de voz que permite solicitudes no autenticadas cuando la opción tunnel.allowNgrokFreeTierLoopbackBypass está explícitamente habilitada. Un atacante externo puede enviar solicitudes falsificadas al endpoint de webhook accesible públicamente sin un encabezado X-Twilio-Signature válido, lo que resulta en un manejo no autorizado de eventos de webhook y posibles ataques de inundación de solicitudes.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 6.5

05 Mar 2026, 23:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 4.8

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-11 01:10


NVD link : CVE-2026-29606

Mitre link : CVE-2026-29606

CVE.ORG link : CVE-2026-29606


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-306

Missing Authentication for Critical Function