PT-2026-35779 · Openclaw · Openclaw

Keensecuritylab

·

Published

2026-03-31

·

Updated

2026-04-30

·

CVE-2026-41395

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description An issue exists in Plivo V3 signature verification where the system canonicalizes query ordering for signatures but hashes raw URLs for replay detection. This allows attackers to reorder query parameters to bypass replay cache detection, enabling the triggering of duplicate voice-call processing using a captured valid signed webhook.
Recommendations Update to version 2026.3.28.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41395
GHSA-8689-GM9G-JGR6

Affected Products

Openclaw