Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN761
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache OpenMeetings versions
                                prior to 9.1.0.
 
=====================================================================

https://lists.apache.org/thread/gt3m3tbzh2o16hv8t373ko56k5fq544x
_____________________________________________________________________


CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Severity: critical 

Affected versions:

- Apache OpenMeetings 5.0.0 before 9.1.0

Description:

Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') vulnerability in Apache OpenMeetings.

This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0.
An attacker with moderator rights in any room can read arbitrary
files accessible to the OS account running the OM server,
including credentials and secrets, via a crafted download request.

Users are recommended to upgrade to version 9.1.0, which fixes
the issue.

This issue is being tracked as OPENMEETINGS-2821 

Credit:

follycat and Y0n3er (finder)

References:

https://openmeetings.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-49488
https://issues.apache.org/jira/browse/OPENMEETINGS-2821


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




