Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.
This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-78cg-fc6c-w44w | Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability |
Wed, 15 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* |
Fri, 10 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache openmeetings |
|
| Vendors & Products |
Apache
Apache openmeetings |
Thu, 09 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 09 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object. This issue affects Apache OpenMeetings: from 3.10 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue. | |
| Title | Apache OpenMeetings: Insufficient checks in FileWebService | |
| Weaknesses | CWE-274 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-10T18:44:45.976Z
Reserved: 2026-03-17T16:01:03.395Z
Link: CVE-2026-33005
Updated: 2026-04-09T16:29:20.600Z
Status : Analyzed
Published: 2026-04-09T16:16:26.823
Modified: 2026-04-15T15:27:05.930
Link: CVE-2026-33005
No data.
OpenCVE Enrichment
Updated: 2026-04-13T13:06:51Z
Github GHSA