CVE-2026-91161: OpenWA: VIEWER API keys can read WhatsApp group invite codes

Published Sep 24, 2026
·
Updated

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetInviteCode MCP tool have no OPERATOR role requirement, allowing a valid VIEWER key scoped to a session to retrieve an active group invite code. The invite code is a transferable WhatsApp bearer capability, so an external account can join a group administered by the session without an OpenWA credential, gain read and post access to the group, and retain membership after the VIEWER key is revoked. Affected deployments are those that issue VIEWER keys to parties who should not be able to add accounts to administered groups; OPERATOR and ADMIN access is intended. This issue is fixed in version 0.23.5.

Affected Software

1 affected component
OpenWA OpenWA<0.23.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenWA to a version that resolves this vulnerability.

    Fixed in 0.23.5

Event History

Sep 24, 2026
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are meaningfully exposed?

Deployments prior to 0.23.5 are affected if they issue session-scoped VIEWER API keys to parties that should not be able to add accounts to WhatsApp groups administered by that session. Deployments where VIEWER-key holders are already authorized to obtain group invite codes have less privilege-boundary impact.

2

What does an attacker need to exploit this issue?

An attacker needs a valid VIEWER API key scoped to the target session. They can use the group invite-code API endpoint or the GroupGetInviteCode MCP tool to retrieve an active invite code for a group administered by that session.

3

What is the impact after an invite code is obtained?

The invite code can be transferred to an external WhatsApp account, which can join the group without an OpenWA credential. That account can read and post in the group and remains a member even if the VIEWER key is later revoked.

4

What should be done if upgrading cannot happen immediately?

Do not issue VIEWER keys to parties that are not authorized to add accounts to administered WhatsApp groups. Restrict this access to the intended OPERATOR or ADMIN roles until the deployment can be updated to 0.23.5.

5

How can administrators determine whether this may already have been abused?

Review whether untrusted or insufficiently authorized parties received session-scoped VIEWER keys and whether unknown external WhatsApp accounts have joined groups administered by those sessions. Revoking a VIEWER key alone does not remove accounts that may already have joined using an obtained invite code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203