CVE 4.3 MEDIUM

Apache OpenMeetings: Insufficient checks in FileWebService_CVE-2026-33005

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.

Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.

This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

Basic Information

ID CVE-2026-33005
Source apache
Published Apr 9, 2026 at 15:52
Modified Apr 10, 2026 at 18:44

Affected Product

Vendor Apache Software Foundation
Product Apache OpenMeetings
Version 3.1.0
Affected Versions Apache Software Foundation Apache OpenMeetings 3.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.