CVE-2026-33005
published 2026-04-09CVE-2026-33005: Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.42%
33.9th percentile
Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.
Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.
This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openmeetings | >= 3.1.0 < 9.0.0 | 9.0.0 |
| apache_software_foundation | apache_openmeetings | >= 3.1.0 < 9.0.0 | 9.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78cg-fc6c-w44w: Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings
ghsa_unreviewed·2026-04-09
CVE-2026-33005 CWE-274 GHSA-78cg-fc6c-w44w: Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings
Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.
Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.
This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
VulDB
Apache OpenMeetings up to 8.x FileWebService insufficient permissions or privileges
vuldb·2026-04-09·CVSS 4.3
CVE-2026-33005 [MEDIUM] Apache OpenMeetings up to 8.x FileWebService insufficient permissions or privileges
A vulnerability, which was classified as problematic, was found in Apache OpenMeetings up to 8.x. This impacts an unknown function of the component FileWebService. Executing a manipulation can lead to improper handling of insufficient permissions or privileges.
This vulnerability is handled as CVE-2026-33005. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
ghsa·2026-04-09
CVE-2026-33005 [MEDIUM] CWE-274 Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
Sny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.
This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published