User Role Misconfiguration Vulnerability in OpenWA API by Rmyndharis
CVE-2026-91161
6.4MEDIUM
What is CVE-2026-91161?
The OpenWA API, used as a self-hosted WhatsApp API gateway, has a security vulnerability allowing users with a VIEWER key to access group invite codes without appropriate role checks. This situation permits users to invite external accounts to groups, granting them unintended read and post capabilities, which undermines the integrity of group management. Effective measures were not in place to restrict this functionality to users with OPERATOR or ADMIN roles. This vulnerability has been effectively addressed in version 0.23.5.
Affected Version(s)
OpenWA < 0.23.5
