- CVE: CVE-2026-49488
- CVSS: 6.5 (Medium · CVSSv3)
- Product: Apache Software Foundation Apache OpenMeetings
- Affected: 5.0.0
- Impact: Apache OpenMeetings: Arbitrary File Read
- Status: No confirmed exploitation yet
- Patched in: 9.1.0
- EPSS: 0.7% (30-day)
- Action: Update to 9.1.0 now
TL;DR
Apache has patched a critical OpenMeetings vulnerability tracked as CVE-2026-49488. The path traversal flaw grants arbitrary file read to any user with moderator rights in a room. Version 9.1.0 fixes the issue, and no exploitation or public proof-of-concept has been confirmed.
Why It Matters
OpenMeetings powers video conferencing, whiteboards, and document collaboration for many self-hosted deployments. Moderator rights are not a high bar, since organizations often hand them to ordinary staff. Consequently, a trusted user can read credentials and secrets belonging to the OS account running the server. That access opens the door to deeper compromise.
How the Attack Works
The bug is an improper limitation of a pathname to a restricted directory, better known as path traversal. A crafted download request escapes the intended directory. As a result, the attacker reads any file the OpenMeetings service account can access. This report covers the mechanism only and includes no exploit steps.
Affected Versions
The OpenMeetings vulnerability affects releases from 5.0.0 up to but not including 9.1.0. Apache rates the issue critical.
Patch and Mitigation Steps
Upgrade to OpenMeetings 9.1.0 from the Apache downloads page. Afterward, review who holds moderator rights and trim the list where possible. Rotating any secrets readable by the server account is also wise. Apache published the full advisory on its security mailing list.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.