CVE-2026-34020

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*

History

15 Apr 2026, 15:21

Type Values Removed Values Added
References () https://lists.apache.org/thread/2h3h9do5tp17xldr0nps1yjmkx4vs3db - () https://lists.apache.org/thread/2h3h9do5tp17xldr0nps1yjmkx4vs3db - Vendor Advisory, Mailing List
References () https://owasp.org/www-community/vulnerabilities/Information_exposure_through_query_strings_in_url - () https://owasp.org/www-community/vulnerabilities/Information_exposure_through_query_strings_in_url - Not Applicable
References () http://www.openwall.com/lists/oss-security/2026/04/09/12 - () http://www.openwall.com/lists/oss-security/2026/04/09/12 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*
First Time Apache openmeetings
Apache

10 Apr 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/09/12 -

09 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 16:16

Updated : 2026-04-15 15:21


NVD link : CVE-2026-34020

Mitre link : CVE-2026-34020

CVE.ORG link : CVE-2026-34020


JSON object : View

Products Affected

apache

  • openmeetings
CWE
CWE-598

Use of GET Request Method With Sensitive Query Strings