Use of GET Request Method With Sensitive Query Strings in Apache OpenMeetings - CVE-2026-34020
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of get request method with sensitive query strings in the REST login endpoint when handling login requests. A remote user can send a login request with username and password in query parameters to disclose sensitive information.