User Role Misconfiguration Vulnerability in OpenWA API by Rmyndharis
CVE-2026-91161

6.4MEDIUM

Key Information:

Vendor

Rmyndharis

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-91161?

The OpenWA API, used as a self-hosted WhatsApp API gateway, has a security vulnerability allowing users with a VIEWER key to access group invite codes without appropriate role checks. This situation permits users to invite external accounts to groups, granting them unintended read and post capabilities, which undermines the integrity of group management. Effective measures were not in place to restrict this functionality to users with OPERATOR or ADMIN roles. This vulnerability has been effectively addressed in version 0.23.5.

Affected Version(s)

OpenWA < 0.23.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.