Path traversal in Apache OpenMeetings - CVE-2026-49488

 

Path traversal in Apache OpenMeetings - CVE-2026-49488

Published: August 25, 2026


Vulnerability identifier: #VU145202
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49488
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to path traversal in the download request handler when processing a crafted download request. A remote user can send a crafted download request to disclose sensitive information.

Exploitation requires moderator rights in any room, and exposed files are limited to those accessible to the operating system account running the server.


Affected software

Apache OpenMeetings

How to mitigate CVE-2026-49488

Install security update from vendor's website.

Apache OpenMeetings - update to 9.1.0

External References

Related Security Bulletins