oss-sec mailing list archives

CVE-2026-33005: Apache OpenMeetings: Insufficient checks in FileWebService


From: Maxim Solodovnik <solomax () apache org>
Date: Thu, 09 Apr 2026 14:18:19 +0000

Severity: moderate 

Affected versions:

- Apache OpenMeetings 3.1.0 before 9.0.0

Description:

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.

Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID 
(metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked 
at FileItemDTO object.

This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

This issue is being tracked as OPENMEETINGS-2812 

Credit:

4ra2n (A code security AI agent) (finder)

References:

https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html
https://openmeetings.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-33005
https://issues.apache.org/jira/browse/OPENMEETINGS-2812


Current thread: