Количество 2
Количество 2
CVE-2026-28446
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.
GHSA-4rj2-gpmh-qq5x
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-28446 OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools. | CVSS3: 9.4 | 1% Низкий | 7 месяцев назад | |
GHSA-4rj2-gpmh-qq5x OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching) | CVSS3: 9.4 | 1% Низкий | 7 месяцев назад |
Уязвимостей на страницу