๐Ÿ” CVE Alert

CVE-2026-91160

HIGH 8.2

OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event stream

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form, even though GET /api/sessions/{sessionId}/qr requires the OPERATOR role. When an allowed session is waiting to be paired, the exposed QR lets the key holder link an external device to the WhatsApp account and then read and send messages outside OpenWA and its audit trail. Keys restricted through allowedSessions remain limited to those sessions, and deployments that issue only OPERATOR or ADMIN keys are not affected. This issue is fixed in version 0.23.5.

CWE CWE-862
Vendor rmyndharis
Product openwa
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for rmyndharis openwa

Be the first to know when new high vulnerabilities affecting rmyndharis openwa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

rmyndharis / OpenWA
< 0.23.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rmyndharis/OpenWA/security/advisories/GHSA-m427-j4h4-9qwj github.com: https://github.com/rmyndharis/OpenWA/pull/1602 github.com: https://github.com/rmyndharis/OpenWA/commit/acc23c3803c07f43791a92e8e48456572fd69bdc github.com: https://github.com/rmyndharis/OpenWA/commit/b9d9ea1c57bde98b7833a5d6e482998703667ef0 github.com: https://github.com/rmyndharis/OpenWA/releases/tag/v0.23.5