CVE-2026-28465: fallo de gravedad alta en OpenClaw voice-call
OpenClaw voice-call < 2026.2.3 - Webhook Verification Bypass via Forwarded Headers
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.2epss 0.7%
probabilidad de explotación
0.7%top 48% de las CVE
explotación observada
noninguna fuente lo reporta
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
OpenClaw · voice-call