Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26319

24
FAUCET Score

CVE-2026-26319 impacts OpenClaw versions 2026.2.13 and below, specifically when the optional @openclaw/voice-call plugin is installed and enabled. The vulnerability allows unauthenticated attackers to forge Telnyx webhook events due to a failure in signature verification when telnyx.publicKey is not configured. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low attack complexity, potentially leading to high integrity impact by allowing arbitrary HTTP POST requests to be treated as legitimate Telnyx events. While not currently listed in KEV, there is community discussion and media coverage, indicating awareness, but no public exploit code is available.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026.2.14CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 4th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.2.14

Vendor Advisories (1)

npmGHSA-4hg8-92x6-h2f3high

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Feb 17, 2026

References

github.com / openclaw/openclaw/commit/29b587e73cbdc941caec573facd16e87d52f007b
Patch
github.com / openclaw/openclaw/commit/f47584fec86d6d73f2d483043a2ad0e7e3c50411
Patch
github.com / openclaw/openclaw/releases/tag/v2026.2.14
ProductRelease Notes
github.com / openclaw/openclaw/security/advisories/GHSA-4hg8-92x6-h2f3
MitigationVendor Advisory