๐Ÿ” CVE Alert

CVE-2026-91161

MEDIUM 6.4

OpenWA: VIEWER API keys can read WhatsApp group invite codes

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetInviteCode MCP tool have no OPERATOR role requirement, allowing a valid VIEWER key scoped to a session to retrieve an active group invite code. The invite code is a transferable WhatsApp bearer capability, so an external account can join a group administered by the session without an OpenWA credential, gain read and post access to the group, and retain membership after the VIEWER key is revoked. Affected deployments are those that issue VIEWER keys to parties who should not be able to add accounts to administered groups; OPERATOR and ADMIN access is intended. This issue is fixed in version 0.23.5.

CWE CWE-863
Vendor rmyndharis
Product openwa
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for rmyndharis openwa

Be the first to know when new medium vulnerabilities affecting rmyndharis openwa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

rmyndharis / OpenWA
< 0.23.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rmyndharis/OpenWA/security/advisories/GHSA-45fh-xj7x-vj2x github.com: https://github.com/rmyndharis/OpenWA/pull/1572 github.com: https://github.com/rmyndharis/OpenWA/commit/a888a0121543426d4e1bf55f9edaed8306ae2699 github.com: https://github.com/rmyndharis/OpenWA/commit/d66439db9653c7aa7cbfb763003c8d3cbc8f623c github.com: https://github.com/rmyndharis/OpenWA/releases/tag/v0.23.5