Path traversal in Apache OpenMeetings - CVE-2026-49488
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the download request handler when processing a crafted download request. A remote user can send a crafted download request to disclose sensitive information.
Exploitation requires moderator rights in any room, and exposed files are limited to those accessible to the operating system account running the server.