PT-2026-31641 · Apache · Apache Openmeetings

4Ra2N

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-34020

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenMeetings versions 3.1.3 through 8.9.99
Description The REST login endpoint uses the HTTP GET method, transmitting the username and password as query parameters. This practice exposes sensitive credentials in server logs, browser history, and potentially through network monitoring.
Recommendations Upgrade to version 9.0.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34020
GHSA-GCVM-C75M-H4P4

Affected Products

Apache Openmeetings