PT-2026-60542 · Unknown · Bigbluebutton
CVE-2026-46351
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions prior to 3.0.21
Description
The bbb-web component generates conference
sessionToken values using insufficiently secure randomness within the Util.java and ApiController.groovy files. This flaw allows a session user to predict the session tokens of other users, potentially leading to user impersonation.Recommendations
Update to version 3.0.21.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton