Improper Authentication in OpenClaw - CVE-2026-28465
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof webhook events.
The vulnerability exists due to improper authentication in webhook verification in the optional voice-call plugin when processing webhook requests behind certain reverse-proxy or forwarding configurations that accept untrusted forwarded headers. A remote attacker can send specially crafted webhook requests with attacker-controlled forwarded headers to spoof webhook events.
The issue affects only installations where the optional voice-call plugin is installed and enabled.