CVE-2026-1332
Unknown
Unknown - Not Provided
Missing Authentication in MeetingHub API Allows Unauthorized Data Access
Publication date: 2026-01-22
Last updated on: 2026-02-17
Assigner: TWCERT/CC
Description
Description
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hamastar | meetinghub_paperless_meetings | to 2025-12-10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in MeetingHub developed by HAMASTAR Technology is a Missing Authentication flaw. This means that unauthenticated remote attackers can access certain API functions without proper verification, allowing them to obtain meeting-related information.
How can this vulnerability impact me? :
This vulnerability can allow unauthorized individuals to access meeting-related information remotely without authentication. This could lead to exposure of sensitive meeting details, potentially compromising confidentiality and privacy.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70