Executive brief
Apache OpenMeetings, a web-based application for video conferencing and collaboration, uses a predictable, hard-coded security key to protect 'remember-me' login cookies. If an administrator has not manually changed this default key, an attacker who obtains a user's session cookie can decrypt it to recover the user's full login credentials. This could lead to unauthorized access to sensitive meetings, private communications, and corporate data.
Technical details
A Use of Hard-coded Cryptographic Key (CWE-321) vulnerability exists in Apache OpenMeetings versions 6.1.0 through 8.0.0. The encryption key and salt used for 'remember-me' cookies are set to static default values in the 'openmeetings.properties' file and are not automatically rotated. If an administrator fails to manually update these default values, the cryptographic protection of the cookies is effectively nullified. An attacker who obtains a 'remember-me' cookie (e.g., via network sniffing or local access) can use the known default keys to decrypt the cookie and extract the user's plaintext credentials. The issue is resolved in version 9.0.0.
Affected products
- Apache OpenMeetings 6.1.0 to 8.0.0 (before 9.0.0)
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory
- 2026-04-09: patched: Fixed in version 9.0.0