Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rmyndharis
Rmyndharis openwa |
|
| Vendors & Products |
Rmyndharis
Rmyndharis openwa |
Thu, 24 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form, even though GET /api/sessions/{sessionId}/qr requires the OPERATOR role. When an allowed session is waiting to be paired, the exposed QR lets the key holder link an external device to the WhatsApp account and then read and send messages outside OpenWA and its audit trail. Keys restricted through allowedSessions remain limited to those sessions, and deployments that issue only OPERATOR or ADMIN keys are not affected. This issue is fixed in version 0.23.5. | |
| Title | OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event stream | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T15:33:28.155Z
Reserved: 2026-09-14T21:20:41.196Z
Link: CVE-2026-91160
Updated: 2026-10-05T14:53:07.505Z
Status : Deferred
Published: 2026-09-24T17:17:09.257
Modified: 2026-10-05T16:17:17.470
Link: CVE-2026-91160
No data.
OpenCVE Enrichment
Updated: 2026-09-25T14:17:02Z
-
CWE-862
Missing Authorization