GHSA-78cg-fc6c-w44w

Suggest an improvement
Source
https://github.com/advisories/GHSA-78cg-fc6c-w44w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-78cg-fc6c-w44w/GHSA-78cg-fc6c-w44w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-78cg-fc6c-w44w
Aliases
  • CVE-2026-33005
Published
2026-04-09T18:31:26Z
Modified
2026-04-10T21:50:40Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
Details

Sny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.

This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-274"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-10T21:24:13Z",
    "nvd_published_at": "2026-04-09T16:16:26Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.apache.openmeetings:openmeetings-parent

Package

Name
org.apache.openmeetings:openmeetings-parent
View open source insights on deps.dev
Purl
pkg:maven/org.apache.openmeetings/openmeetings-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10
Fixed
9.0.0

Affected versions

4.*
4.0.0
4.0.1
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.9
4.0.10
4.0.11
5.*
5.0.0-M1
5.0.0-M2
5.0.0-M3
5.0.0-M4
5.0.0
5.1.0
6.*
6.2.0
6.3.0
7.*
7.0.0
7.2.0
8.*
8.0.0
8.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-78cg-fc6c-w44w/GHSA-78cg-fc6c-w44w.json"