CVE-2026-34020
published 2026-04-09CVE-2026-34020: Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.51%
40.0th percentile
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact
This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openmeetings | >= 3.1.3 < 9.0.0 | 9.0.0 |
| apache_software_foundation | apache_openmeetings | >= 3.1.3 < 9.0.0 | 9.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcvm-c75m-h4p4: Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings
ghsa_unreviewed·2026-04-09
CVE-2026-34020 CWE-598 GHSA-gcvm-c75m-h4p4: Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact
This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
GHSA
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
ghsa·2026-04-09
CVE-2026-34020 [HIGH] CWE-598 Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact
This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0.
Users are recommended to upgrade to version 9.0.0, which fixes the issue.
VulDB
Apache OpenMeetings up to 8.x REST Login Endpoint username/password information disclosure
vuldb·2026-04-09·CVSS 7.5
CVE-2026-34020 [HIGH] Apache OpenMeetings up to 8.x REST Login Endpoint username/password information disclosure
A vulnerability was found in Apache OpenMeetings up to 8.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the component REST Login Endpoint. The manipulation of the argument username/password results in information disclosure.
This vulnerability was named CVE-2026-34020. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published