CVE-2026-91160

Source
https://cve.org/CVERecord?id=CVE-2026-91160
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91160.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91160
Aliases
  • GHSA-m427-j4h4-9qwj
Published
2026-09-24T16:42:02Z
Modified
2026-09-26T03:48:27Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event stream
Details

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form, even though GET /api/sessions/{sessionId}/qr requires the OPERATOR role. When an allowed session is waiting to be paired, the exposed QR lets the key holder link an external device to the WhatsApp account and then read and send messages outside OpenWA and its audit trail. Keys restricted through allowedSessions remain limited to those sessions, and deployments that issue only OPERATOR or ADMIN keys are not affected. This issue is fixed in version 0.23.5.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91160.json"
}
References

Affected packages

Git / github.com/rmyndharis/openwa

Affected ranges

Type
GIT
Repo
https://github.com/rmyndharis/openwa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.23.5"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

java-sdk-v0.*
java-sdk-v0.1.0
java-sdk-v0.1.1
java-sdk-v0.3.0
java-sdk-v0.4.0
java-sdk-v0.5.0
js-sdk-v0.*
js-sdk-v0.2.0
js-sdk-v0.3.0
js-sdk-v0.4.0
js-sdk-v0.5.0
php-sdk-v0.*
php-sdk-v0.2.0
php-sdk-v0.3.0
php-sdk-v0.4.0
php-sdk-v0.5.0
py-sdk-v0.*
py-sdk-v0.2.0
py-sdk-v0.3.0
py-sdk-v0.4.0
py-sdk-v0.5.0
sdk/go/v0.*
sdk/go/v0.2.0
sdk/go/v0.3.0
sdk/go/v0.4.0
sdk/go/v0.5.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.10.0
v0.10.1
v0.10.10
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.13.0
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.14.4
v0.14.5
v0.14.6
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.2.0
v0.2.1
v0.2.10
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9
v0.20.0
v0.21.0
v0.22.0
v0.23.0
v0.23.1
v0.23.2
v0.23.3
v0.23.4
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v0.7.10
v0.7.11
v0.7.12
v0.7.13
v0.7.14
v0.7.15
v0.7.16
v0.7.17
v0.7.18
v0.7.19
v0.7.2
v0.7.20
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.10
v0.8.11
v0.8.12
v0.8.13
v0.8.14
v0.8.15
v0.8.16
v0.8.17
v0.8.18
v0.8.19
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91160.json"