CVE-2026-33266

CVE-2026-33266: Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt

Vendor Apache Software Foundation
Product Apache OpenMeetings
Weakness CWE-321
Published April 9, 2026
Last update April 10, 2026

CVSS base score

What the vulnerability does

01Description

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get full user credentials. This issue affects Apache OpenMeetings: from 6.1.0 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

Key dates

02Disclosure timeline

April 9, 2026 CVE published
April 10, 2026 Record updated

Related vulnerabilities

04Related CVE