---
id: CVE-2026-28465
title: >-
  OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper
  authentication vulnerability in webhook verification that allows remote
  attackers to bypass verification by supplying untrusted forwarded headers
summary: >-
  OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper
  authentication vulnerability in webhook verification that allows remote
  attackers to bypass verification by supplying untrusted forwarded headers.
  Attackers can sp…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-290
vendor: openclaw
product: openclaw
affected:
  - openclaw < 2026.2.3
patched:
  - openclaw 2026.2.3
published: '2026-03-05'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:16:40.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28465'
references:
  - url: >-
      https://github.com/openclaw/openclaw/commit/a749db9820eb6d6224032a5a34223d286d2dcc2f
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-voice-call-webhook-verification-bypass-via-forwarded-headers
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-09T17:50:55.892165Z'
epss: 0.00374
epssPercentile: 0.31305
ingestedAt: '2026-09-17T18:25:15.967Z'
---

## Overview

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.

## Affected

- `openclaw < 2026.2.3`

## Remediation

Upgrade past the affected range:

- `openclaw 2026.2.3`
