WebSocket Vulnerability in OpenWA WhatsApp API Gateway
CVE-2026-91160

8.2HIGH

Key Information:

Vendor

Rmyndharis

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-91160?

The OpenWA WhatsApp API gateway contains a vulnerability allowing the /events WebSocket gateway to deliver the session.qr event to a VIEWER API key, which should be restricted to only those with an OPERATOR role. This flaw permits unauthorized linking of external devices to a WhatsApp account, enabling the holder of the compromised API key to read and send messages without an audit trail. The risk is mitigated in version 0.23.5, which addresses the WebSocket's handling of events tied to user sessions.

Affected Version(s)

OpenWA < 0.23.5

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.