Triple Security Advisory Prompts Immediate Upgrade to Apache OpenMeetings Version 9.0.0
ID: 132aab70-e389-5b20-8f94-58662dc28ba2
STIX ID: report--132aab70-e389-5b20-8f94-58662dc28ba2
Feed Name: securityonline.info
Apache OpenMeetings released v9.0.0 to address three disclosed vulnerabilities: CVE-2026-33005 (improper handling of privileges exposing file/folder metadata to authenticated users), CVE-2026-33266 (hard-coded remember-me cookie encryption key that can allow full credential compromise if default key remains), and CVE-2026-34020 (REST login implemented with HTTP GET passing credentials in query parameters). Multiple versions are affected (starting from 3.1.0 / 3.1.3 / 6.1.0 depending on the issue) and users are strongly advised to upgrade to 9.0.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
