critical · CVSS v3 8.8 · CVSS v4 8.7 · EPSS 0.00246
CVE-2026-100544
CVE-2026-100544 exposes the openclaw/voice-call package to remote callers who can trigger owner‑only tools without identity verification. Th
Overview
CVE-2026-100544 exposes the openclaw/voice-call package to remote callers who can trigger owner‑only tools without identity verification. The flaw allows attackers to read, modify, or execute commands on the agent. It is fixed in version 2026.8.1.
Description
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
Impact
Confidentiality and integrity of data handled by the agent are compromised when a remote caller can invoke privileged tools. Availability may also be affected if malicious commands disrupt services. Defenders of deployments using inbound voice calls are directly impacted.
Remediation
Upgrade to openclaw/voice-call 2026.8.1 or later. Disable inbound calling if not required, or enforce strict owner‑only policies. Verify that caller identity is propagated and monitor logs for unauthorized tool usage.
Risk context
The vulnerability is rated critical with a CVSS v3 score of 8.8, but the EPSS score of 0.00246 indicates a low likelihood of exploitation. Defenders should prioritize patching while maintaining vigilance.
Affected products
- openclaw/voice-call
- openclaw
- voice-call
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- 8.7
- EPSS
- 0.00246