CVE-2026-33266
published 2026-04-09CVE-2026-33266: Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.23%
14.4th percentile
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get full user credentials.
This issue affects Apache OpenMeetings: from 6.1.0 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openmeetings | >= 6.1.0 < 9.0.0 | 9.0.0 |
| apache_software_foundation | apache_openmeetings | >= 6.1.0 < 9.0.0 | 9.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqxq-w68r-wg85: Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings
ghsa_unreviewed·2026-04-09
CVE-2026-33266 CWE-321 GHSA-wqxq-w68r-wg85: Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get full user credentials.
This issue affects Apache OpenMeetings: from 6.1.0 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
GHSA
Apache OpenMeetings Uses Hard-coded Cryptographic Key
ghsa·2026-04-09
CVE-2026-33266 [HIGH] CWE-321 Apache OpenMeetings Uses Hard-coded Cryptographic Key
Apache OpenMeetings Uses Hard-coded Cryptographic Key
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get full user credentials.
This issue affects Apache OpenMeetings: from 6.1.0 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
VulDB
Apache OpenMeetings up to 8.x a one-way hash with a predictable salt
vuldb·2026-04-09·CVSS 7.5
CVE-2026-33266 [HIGH] Apache OpenMeetings up to 8.x a one-way hash with a predictable salt
A vulnerability has been found in Apache OpenMeetings up to 8.x and classified as problematic. Affected is an unknown function. The manipulation leads to use of a one-way hash with a predictable salt.
This vulnerability is uniquely identified as CVE-2026-33266. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published