CVE-2026-26319 impacts OpenClaw versions 2026.2.13 and below, specifically when the optional @openclaw/voice-call plugin is installed and enabled. The vulnerability allows unauthenticated attackers to forge Telnyx webhook events due to a failure in signature verification when telnyx.publicKey is not configured. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low attack complexity, potentially leading to high integrity impact by allowing arbitrary HTTP POST requests to be treated as legitimate Telnyx events. While not currently listed in KEV, there is community discussion and media coverage, indicating awareness, but no public exploit code is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.2.14CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.