CVE-2026-28465

O

penClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers.

Configurations

No configuration.

History

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-05 22:16


NVD link : CVE-2026-28465

Mitre link : CVE-2026-28465

CVE.ORG link : CVE-2026-28465


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity