An authentication bypass in the optional voice-call extension/plugin allowed unapproved or anonymous callers to reach the voice-call agent when inbound policy was set to allowlist or pairing.
Deployments that do not install/enable the voice-call extension are not affected.
openclaw (npm): <= 2026.2.1>= 2026.2.2In affected versions (for example 2026.2.1), the inbound allowlist check in extensions/voice-call/src/manager.ts used suffix-based matching and accepted empty caller IDs after normalization.
This allowed two bypasses:
from values normalized to an empty string, which caused the allowlist predicate to evaluate as allowed.inboundPolicy: allowlist and allowFrom: ["+15550001234"].15550001234 (for example +99915550001234). The call is accepted.Only operators who install/enable the optional voice-call extension and use inboundPolicy=allowlist or pairing could have inbound access controls bypassed, potentially allowing unauthorized callers to reach auto-response and tool execution.
The fix hardens inbound policy handling:
Fix commit(s):
f8dfd034f5d9235c5485f492a9e4ccc114e97fdbThanks @simecek for reporting.
{
"cwe_ids": [
"CWE-287"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-17T21:36:34Z",
"nvd_published_at": "2026-03-05T22:16:16Z",
"severity": "CRITICAL"
}