CVE-2026-34020

CVE-2026-34020: Apache OpenMeetings: Login Credentials Passed via GET Query Parameters

Vendor Apache Software Foundation
Product Apache OpenMeetings
Weakness CWE-598
Published April 9, 2026
Last update April 10, 2026

CVSS base score

What the vulnerability does

Description

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

Key dates

Disclosure timeline

April 9, 2026 CVE published
April 10, 2026 Record updated