Apache disclosed two moderate-severity vulnerabilities in Apache OpenMeetings that affect releases before 9.0.0, including a credential exposure issue tracked as CVE-2026-34020. The flaw stems from the REST login endpoint sending usernames and passwords through HTTP GET query parameters, which can leave credentials exposed in browser history, logs, referrers, and other URL-handling systems. Apache linked the issue to internal ticket OPENMEETINGS-2816 and fixed it in version 9.0.0.
Apache also disclosed CVE-2026-33005, an improper privilege-handling flaw in FileWebService that lets any authenticated user retrieve metadata for files and subfolders in arbitrary folders by ID. The exposed information includes fields such as id, type, and name, though not file contents. Both issues were credited to 4ra2n, described as a code security AI agent, and Apache advised users to upgrade to OpenMeetings 9.0.0 to remediate the vulnerabilities.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-33005 and CVE-2026-34020 affecting Apache OpenMeetings versions before 9.0.0, covering insufficient checks in FileWebService and exposure of login credentials in GET query parameters. Apache recommended upgrading to version 9.0.0, which remediates the issues.
Apache created JIRA issue OPENMEETINGS-2816 to track a vulnerability in OpenMeetings where login credentials were passed via HTTP GET query parameters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceissues.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.