{"api_version":"1","generated_at":"2026-04-09T20:38:23+00:00","cve":"CVE-2026-33005","urls":{"html":"https://cve.report/CVE-2026-33005","api":"https://cve.report/api/cve/CVE-2026-33005.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-33005","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-33005"},"summary":{"title":"Apache OpenMeetings: Insufficient checks in FileWebService","description":"Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.\n\nAny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.\n\nThis issue affects Apache OpenMeetings: from 3.10 before 9.0.0.\n\nUsers are recommended to upgrade to version 9.0.0, which fixes the issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-04-09 16:16:26","updated_at":"2026-04-09 17:16:24"},"problem_types":["CWE-274","CWE-274 CWE-274 Improper Handling of Insufficient Privileges"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/pttoprd628g3xr6lpp3bm1z8m3z8t4p7","name":"https://lists.apache.org/thread/pttoprd628g3xr6lpp3bm1z8m3z8t4p7","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html","name":"https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/04/09/10","name":"http://www.openwall.com/lists/oss-security/2026/04/09/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-33005","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33005","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache OpenMeetings","version":"affected 3.1.0 9.0.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"4ra2n (A code security AI agent)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-04-09T16:29:20.600Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/04/09/10"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache OpenMeetings","vendor":"Apache Software Foundation","versions":[{"lessThan":"9.0.0","status":"affected","version":"3.1.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"4ra2n (A code security AI agent)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.</p><p>Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at&nbsp;FileItemDTO&nbsp;object.</p><p>This issue affects Apache OpenMeetings: from 3.10 before 9.0.0.</p><p>Users are recommended to upgrade to version 9.0.0, which fixes the issue.</p>"}],"value":"Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.\n\nAny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.\n\nThis issue affects Apache OpenMeetings: from 3.10 before 9.0.0.\n\nUsers are recommended to upgrade to version 9.0.0, which fixes the issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-274","description":"CWE-274 Improper Handling of Insufficient Privileges","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-09T15:52:50.770Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["technical-description"],"url":"https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html"},{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/pttoprd628g3xr6lpp3bm1z8m3z8t4p7"}],"source":{"defect":["OPENMEETINGS-2812"],"discovery":"EXTERNAL"},"title":"Apache OpenMeetings: Insufficient checks in FileWebService","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-33005","datePublished":"2026-04-09T15:52:50.770Z","dateReserved":"2026-03-17T16:01:03.395Z","dateUpdated":"2026-04-09T16:29:20.600Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-04-09 16:16:26","lastModifiedDate":"2026-04-09 17:16:24","problem_types":["CWE-274","CWE-274 CWE-274 Improper Handling of Insufficient Privileges"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"33005","Ordinal":"1","Title":"Apache OpenMeetings: Insufficient checks in FileWebService","CVE":"CVE-2026-33005","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"33005","Ordinal":"1","NoteData":"Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.\n\nAny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.\n\nThis issue affects Apache OpenMeetings: from 3.10 before 9.0.0.\n\nUsers are recommended to upgrade to version 9.0.0, which fixes the issue.","Type":"Description","Title":"Apache OpenMeetings: Insufficient checks in FileWebService"}]}}}