THREAT OPS › Threat News › [NVD] CVE-2026-28465 (MEDIUM 5.9) — OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarde
[NVD] CVE-2026-28465 (MEDIUM 5.9) — OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarde
CVE-2026-28465 CVSS: 5.9 MEDIUM Published: 2026-03-05T22:16:19.593
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configur
Indicators of compromise
- CVE-2026-28465cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-28465