SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-49488

MEDIUM · CVSS 6.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Apache OpenMeetings versions 5.0.0 through 9.0.0 are vulnerable to a path traversal flaw that allows an attacker with moderator rights to access arbitrary files on the server, potentially exposing sensitive information such as credentials. Organizations using affected versions should prioritize upgrading to version 9.1.0 to mitigate this risk and protect their systems from unauthorized data access.

CVE
CVE-2026-49488
Severity
MEDIUM
CVSS
6.5
EPSS
0.53%
Apache

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)