logo

Triple Security Advisory Prompts Immediate Upgrade to Apache OpenMeetings Version 9.0.0

ID: 132aab70-e389-5b20-8f94-58662dc28ba2

STIX ID: report--132aab70-e389-5b20-8f94-58662dc28ba2

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache OpenMeetings released v9.0.0 to address three disclosed vulnerabilities: CVE-2026-33005 (improper handling of privileges exposing file/folder metadata to authenticated users), CVE-2026-33266 (hard-coded remember-me cookie encryption key that can allow full credential compromise if default key remains), and CVE-2026-34020 (REST login implemented with HTTP GET passing credentials in query parameters). Multiple versions are affected (starting from 3.1.0 / 3.1.3 / 6.1.0 depending on the issue) and users are strongly advised to upgrade to 9.0.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.