{"schema_version": "1.6.1", "id": "CVE-2026-49488", "summary": "Arbitrary File Read", "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings.\n\nThis issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0.\nAn attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.\n\nUsers are recommended to upgrade to version 9.1.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "5.0.0"}, {"fixed": "9.1.0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/74zf32shox9oy62b7t55mvcj874bxqnj"}]}