Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings.

This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0.
An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.

Users are recommended to upgrade to version 9.1.0, which fixes the issue.
Published: 2026-07-14
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache OpenMeetings is vulnerable to a path traversal flaw that allows a user with moderator rights in any room to craft a download request and read any file accessible to the OS account on which the OM server runs. The flaw grants the ability to exfiltrate sensitive data such as credentials and secrets stored on the server, thereby compromising the confidentiality of all data stored on the affected instance. The issue does not lead to code execution or denial of service by itself. The vulnerability is identified as CWE‑22.

Affected Systems

The vulnerability affects all Apache OpenMeetings releases from 5.0.0 up to, but not including, 9.1.0. Users running these affected versions must review their deployments to determine whether moderators have been granted access.

Risk and Exploitability

Exploitation requires that the attacker already possess moderator rights within a room, so the risk is limited to environments where such roles are present. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Given the combination of privileged user prerequisites and low exploit probability, the overall risk is moderate, but the impact of successful exploitation is high due to sensitive data exposure. Because the attacker must target a running OpenMeetings instance with an existing moderator account, immediate remediation is still advised to eliminate the disclosure path.

Generated by OpenCVE AI on July 31, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache OpenMeetings to version 9.1.0 or later, which includes the path traversal fix
  • If upgrading cannot be performed immediately, restrict moderator permissions to a minimal, trusted set of users and audit the moderator role to ensure that only authorized personnel retain that level of access
  • Configure web application firewall or application layer filtering to block requests containing path traversal patterns such as "..\\" or "../" in the download URL

Generated by OpenCVE AI on July 31, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache openmeetings
Vendors & Products Apache
Apache openmeetings

Tue, 14 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.
Title Apache OpenMeetings: Arbitrary File Read
Weaknesses CWE-22
References

Subscriptions

Apache Openmeetings
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-15T15:13:20.235Z

Reserved: 2026-05-31T06:53:32.094Z

Link: CVE-2026-49488

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')