Junglewise Threat Intelligence

CVE-2026-49488: Apache OpenMeetings path traversal in file download functionality

CVE-2026-49488 · Severity: info · Published 2026-07-14

Technologies: Apache Software Foundation OpenMeetings. Vendors: Apache Software Foundation.

Executive brief

Apache OpenMeetings, a web-based application for video conferencing and collaboration, is vulnerable to a security flaw that allows room moderators to access sensitive files on the server. By sending a specially crafted download request, an authorized moderator could steal system credentials, configuration secrets, or other private data stored on the host machine. This could lead to a full compromise of the server or unauthorized access to other corporate systems.

Technical details

A path traversal vulnerability (CWE-22) exists in Apache OpenMeetings versions 5.0.0 through 9.0.x. The flaw resides in the file download functionality, where the application fails to properly sanitize or limit pathnames to restricted directories. An attacker authenticated with moderator privileges in any room can submit a crafted download request to escape the intended directory and read any file accessible to the operating system account running the OpenMeetings server. This includes sensitive configuration files, credentials, and application secrets. The issue is resolved in version 9.1.0.

Affected products

  • Apache Software Foundation OpenMeetings 5.0.0 to 9.0.x (fixed in 9.1.0)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in version 9.1.0

References

Related threats