https://seclists.org/oss-sec/2026/q2/64: CVE-2026-33266: Apache OpenMeetings: Hardcoded member-Me Cookie Encryption Key and Salt
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Apache OpenMeetings>=6.1.0<9.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-33266?
The severity of CVE-2026-33266 is classified as important.
2
Which versions of Apache OpenMeetings are affected by CVE-2026-33266?
CVE-2026-33266 affects Apache OpenMeetings versions 6.1.0 before 9.0.0.
3
How do I fix CVE-2026-33266?
To fix CVE-2026-33266, upgrade to Apache OpenMeetings version 9.0.0 or later.
4
What is the main issue with CVE-2026-33266?
The main issue with CVE-2026-33266 is the use of a hard-coded cookie encryption key and salt in the application's configuration.
5
Why is the hard-coded encryption key in CVE-2026-33266 a concern?
The hard-coded encryption key in CVE-2026-33266 is a concern because it can be exploited by attackers to bypass security measures and decrypt sensitive user data.