Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-28446 โ€” AI Deep Analysis Summary

CVSS 9.4 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: OpenClaw < 2026.2.1 has a critical **Inbound Allowlist Policy Bypass**. ๐Ÿ“‰ **Consequences**: Attackers can bypass access controls via voice-call extensions, leading to unauthorized remote access.

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: Flaw in **Inbound Allowlist Policy Validation**. Specifically, it allows bypass via **Empty Caller ID** and **Suffix Matching** logic errors. (CWE not specified in data).

Q3Who is affected? (Versions/Components)

๐Ÿ‘ฅ **Affected**: **OpenClaw** (Open-source AI Assistant). ๐Ÿ“ฆ **Versions**: All versions **before 2026.2.1**. ๐Ÿข **Vendor**: OpenClaw.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Actions**: Remote attackers can **bypass inbound access control**. โš ๏ธ **Impact**: High Confidentiality & Integrity impact (CVSS C:H, I:H), Low Availability impact (A:L).

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: **LOW**. ๐ŸŒ **Network**: Remote (AV:N). ๐Ÿ”‘ **Auth**: None required (PR:N). ๐Ÿ‘๏ธ **UI**: None required (UI:N). ๐ŸŽฏ **Complexity**: Low (AC:L).

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿงช **Public Exp?**: No specific PoC code provided in data. ๐Ÿ“ข **Advisories**: VulnCheck and GitHub Security Advisory (GHSA-4rj2-gpmh-qq5x) confirm the flaw exists.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for **OpenClaw** installations. ๐Ÿ“ž **Focus**: Check **voice-call extensions** for allowlist policy configurations. ๐Ÿ†š **Version**: Verify if version is < 2026.2.1.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed?**: **YES**. ๐Ÿ› ๏ธ **Patch**: Version **2026.2.1** and later. ๐Ÿ“ **Commit**: See GitHub commit f8dfd034f5d9235c5485f492a9e4ccc114e97fdb.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: Mitigate by restricting **inbound voice-call extensions**. ๐Ÿšซ **Block**: Empty Caller IDs if possible. ๐Ÿ›‘ **Isolate**: Limit network access to the service until patched.

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **HIGH**. ๐Ÿ“ˆ **CVSS**: High severity (C:H, I:H). โณ **Action**: Patch immediately to 2026.2.1+ to prevent remote bypass attacks.