https://seclists.org/oss-sec/2026/q2/65: CVE-2026-34020: Apache OpenMeetings: Login Cdentials Passed via GET Query Parameters
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Apache OpenMeetings>=3.1.3<9.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-34020?
The severity of CVE-2026-34020 is classified as moderate.
2
Which versions of Apache OpenMeetings are affected by CVE-2026-34020?
CVE-2026-34020 affects Apache OpenMeetings versions 3.1.3 and earlier than 9.0.0.
3
How does CVE-2026-34020 exploit the Apache OpenMeetings application?
CVE-2026-34020 exploits the application by allowing login credentials to be transmitted via GET query parameters.
4
How do I fix CVE-2026-34020?
To fix CVE-2026-34020, upgrade Apache OpenMeetings to version 9.0.0 or later.
5
What are the implications of CVE-2026-34020 for user data security?
CVE-2026-34020 poses a risk to user data security due to the exposure of sensitive login information in URLs.