CVE-2026-41395: OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41395?
CVE-2026-41395 is rated as high severity with a CVSS score of 8.2.
How do I fix CVE-2026-41395?
To fix CVE-2026-41395, upgrade OpenClaw to version 2026.3.28 or later.
What type of vulnerability is CVE-2026-41395?
CVE-2026-41395 is a webhook replay vulnerability caused by query parameter reordering.
Which versions of OpenClaw are affected by CVE-2026-41395?
OpenClaw versions prior to 2026.3.28 are affected by CVE-2026-41395.
What is the impact of CVE-2026-41395 if exploited?
If exploited, CVE-2026-41395 allows attackers to bypass replay cache detection and trigger duplicate voice-call processes.