Impact
Apache OpenMeetings is vulnerable to a path traversal flaw that allows a user with moderator rights in any room to craft a download request and read any file accessible to the OS account on which the OM server runs. The flaw grants the ability to exfiltrate sensitive data such as credentials and secrets stored on the server, thereby compromising the confidentiality of all data stored on the affected instance. The issue does not lead to code execution or denial of service by itself. The vulnerability is identified as CWE‑22.
Affected Systems
The vulnerability affects all Apache OpenMeetings releases from 5.0.0 up to, but not including, 9.1.0. Users running these affected versions must review their deployments to determine whether moderators have been granted access.
Risk and Exploitability
Exploitation requires that the attacker already possess moderator rights within a room, so the risk is limited to environments where such roles are present. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Given the combination of privileged user prerequisites and low exploit probability, the overall risk is moderate, but the impact of successful exploitation is high due to sensitive data exposure. Because the attacker must target a running OpenMeetings instance with an existing moderator account, immediate remediation is still advised to eliminate the disclosure path.
OpenCVE Enrichment