HarborGuard / CVE
Back to search
HIGHCVE-2026-28465Published Modified CNA VulnCheck

CVE-2026-28465: OpenClaw voice-call < 2026.2.3 - Webhook Verification Bypass via Forwarded Headers

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.

Metrics

CVSS v4.0
8.2
Severity
HIGH
Fixed in
2026.2.3
Affected Products
1

Fix available

2026.2.3
Patch commits
Affected packages
  • OpenClaw / voice-call
    < 2026.2.3 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N