https://seclists.org/oss-sec/2026/q2/63: CVE-2026-33005: Apache OpenMeetings: Insufficient checks in FileWebService
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Apache OpenMeetings>=3.1.0<9.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-33005?
CVE-2026-33005 has a moderate severity level.
2
Which versions are affected by CVE-2026-33005?
CVE-2026-33005 affects Apache OpenMeetings versions 3.1.0 before 9.0.0.
3
What is the vulnerability described in CVE-2026-33005?
CVE-2026-33005 describes an insufficient checks vulnerability in Apache OpenMeetings that allows registered users to access unauthorized files through the FileWebService.
4
How do I fix CVE-2026-33005?
To fix CVE-2026-33005, upgrade Apache OpenMeetings to version 9.0.0 or later.
5
What are the potential risks of CVE-2026-33005?
The risks of CVE-2026-33005 include unauthorized access to sensitive files and folders by any registered user.