Junglewise Threat Intelligence

CVE-2026-33266: Apache OpenMeetings hard-coded cryptographic key in remember-me cookies

CVE-2026-33266 · Severity: high · CVSS 7.5 · Published 2026-04-09

Technologies: org.apache.openmeetings:openmeetings-parent (Maven), Apache Software Foundation OpenMeetings. Vendors: Apache, Maven, Apache Software Foundation.

Executive brief

Apache OpenMeetings, a web-based application for video conferencing and collaboration, uses a predictable, hard-coded security key to protect 'remember-me' login cookies. If an administrator has not manually changed this default key, an attacker who obtains a user's session cookie can decrypt it to recover the user's full login credentials. This could lead to unauthorized access to sensitive meetings, private communications, and corporate data.

Technical details

A Use of Hard-coded Cryptographic Key (CWE-321) vulnerability exists in Apache OpenMeetings versions 6.1.0 through 8.0.0. The encryption key and salt used for 'remember-me' cookies are set to static default values in the 'openmeetings.properties' file and are not automatically rotated. If an administrator fails to manually update these default values, the cryptographic protection of the cookies is effectively nullified. An attacker who obtains a 'remember-me' cookie (e.g., via network sniffing or local access) can use the known default keys to decrypt the cookie and extract the user's plaintext credentials. The issue is resolved in version 9.0.0.

Affected products

  • Apache OpenMeetings 6.1.0 to 8.0.0 (before 9.0.0)

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory
  • 2026-04-09: patched: Fixed in version 9.0.0

References

Related threats