Aller au contenu

Fiche vulnérabilité

CVE-2026-28465 : faille élevée openclaw openclaw (CVSS 7.5)

Description

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
5 mars 2026
Dernière mise à jour
17 sept. 2026

Produits concernés

  • openclaw openclaw

Références

Rechercher une autre vulnérabilité dans la base CVE