Use of hard-coded credentials in Apache OpenMeetings - CVE-2026-33266
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of a hard-coded cryptographic key in remember-me cookie encryption in Apache OpenMeetings when processing a stolen remember-me cookie from a logged-in user. A remote user can use a stolen cookie encrypted with the default key to disclose sensitive information.
Exploitation requires that the default encryption key has not been changed and that a remember-me cookie has been stolen from a logged-in user.