Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <5fe9dbb2-d948-7040-fa65-cf9ebf8f9af2@apache.org>
Date: Thu, 09 Apr 2026 14:18:19 +0000
From: Maxim Solodovnik <solomax@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-33005: Apache OpenMeetings: Insufficient checks in
 FileWebService 

Severity: moderate 

Affected versions:

- Apache OpenMeetings 3.1.0 before 9.0.0

Description:

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.

Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.

This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

This issue is being tracked as OPENMEETINGS-2812 

Credit:

4ra2n (A code security AI agent) (finder)

References:

https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html
https://openmeetings.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-33005
https://issues.apache.org/jira/browse/OPENMEETINGS-2812

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.