CVE-2026-28465: Openclaw

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.

Affected products

  • Openclaw Openclaw: before 2026.2.3 (fixed in 2026.2.3)

Published 2026-03-05. Last modified 2026-09-17.