CVE-2026-28446: OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28446?
CVE-2026-28446 is classified as a medium severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-28446?
To mitigate CVE-2026-28446, update OpenClaw to version 2026.2.1 or later.
What products are affected by CVE-2026-28446?
CVE-2026-28446 affects OpenClaw versions prior to 2026.2.1 with the voice-call extension enabled.
What is the nature of the vulnerability in CVE-2026-28446?
CVE-2026-28446 involves an inbound allowlist policy bypass through empty caller ID and suffix matching.
Can CVE-2026-28446 lead to unauthorized access?
Yes, CVE-2026-28446 can potentially allow unauthorized access by bypassing caller ID restrictions.