https://seclists.org/oss-sec/2026/q3/140: CVE-2026-49488: Apache OpenMeetings: Arbitrary File ad
Published Jul 14, 2026
·Updated
Affected Software
1 affected component
Apache OpenMeetings>=5.0.0<9.1.0
Frequently Asked Questions
1
What is the severity of CVE-2026-49488?
CVE-2026-49488 has been classified as critical.
2
What versions of Apache OpenMeetings are affected by CVE-2026-49488?
CVE-2026-49488 affects Apache OpenMeetings versions 5.0.0 before 9.1.0.
3
How do I fix CVE-2026-49488?
The fix for CVE-2026-49488 is to upgrade Apache OpenMeetings to version 9.1.0 or later.
4
What type of vulnerability is CVE-2026-49488?
CVE-2026-49488 is a Path Traversal vulnerability allowing arbitrary file access.
5
Can an attacker exploit CVE-2026-49488 without being a moderator?
No, an attacker must have moderator privileges to exploit CVE-2026-49488.