Severity: moderate 

Affected versions:

- Apache OpenMeetings 3.1.0 before 9.0.0

Description:

Improper Handling of Insufficient Privileges vulnerability in Apache 
OpenMeetings.

Any registered user can query web service with their credentials and get 
files/sub-folders of any folder by ID (metadata only NOT contents). Metadata 
includes id, type, name and some other field. Full list of fields get be 
checked at FileItemDTO object.

This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

This issue is being tracked as OPENMEETINGS-2812 

Credit:

4ra2n (A code security AI agent) (finder)

References:

https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html
https://openmeetings.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-33005
https://issues.apache.org/jira/browse/OPENMEETINGS-2812

Reply via email to