CVE-2026-34020

CWE-5985 documents5 sources
Severity
7.5HIGH
No vector
EPSS
0.0%
top 91.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9

Description

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

Affected Packages2 packages

🔴Vulnerability Details

4
GHSA
GHSA-gcvm-c75m-h4p4: Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings2026-04-09
GHSA
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings2026-04-09
CVEList
Apache OpenMeetings: Login Credentials Passed via GET Query Parameters2026-04-09
VulDB
Apache OpenMeetings up to 8.x REST Login Endpoint username/password information disclosure2026-04-09
CVE-2026-34020 (HIGH CVSS 7.5) | Use of GET Request Method With Sens | cvebase.io