Improper Authorization in Apache OpenMeetings - CVE-2026-33005
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in FileWebService when handling authenticated web service queries for folder identifiers. A remote user can query the service with valid credentials and enumerate files and sub-folders of arbitrary folders by ID to disclose sensitive information.
Only metadata is exposed, including fields such as identifiers, types, and names; file contents are not disclosed.