CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings.
This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.
Users are recommended to upgrade to version 9.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache OpenMeetingsto a version that resolves this vulnerability.Fixed in 9.1.0Patch CVE-2026-49488
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49488?
The severity of CVE-2026-49488 is medium with a CVSS score of 6.5.
How do I fix CVE-2026-49488?
To fix CVE-2026-49488, update Apache OpenMeetings to version 9.1.0 or later.
What type of vulnerability is CVE-2026-49488?
CVE-2026-49488 is a Path Traversal vulnerability.
Who is affected by CVE-2026-49488?
Apache OpenMeetings versions from 5.0.0 to prior to 9.1.0 are affected by CVE-2026-49488.
What can an attacker do with CVE-2026-49488?
An attacker with moderator rights can read arbitrary files accessible to the OS account running the OpenMeetings server.