๐Ÿ” CVE Alert

CVE-2026-46355

HIGH 7.1

BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting because handleJoinExistingUser was a routable controller action rather than a private helper. This issue is fixed in version 3.0.23.

CWE CWE-287
Vendor bigbluebutton
Product bigbluebutton
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for bigbluebutton bigbluebutton

Be the first to know when new high vulnerabilities affecting bigbluebutton bigbluebutton are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

bigbluebutton / bigbluebutton
< 3.0.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-38fw-2gq7-ccgr github.com: https://github.com/bigbluebutton/bigbluebutton/commit/972b04e474e195cbd708b5b3f0485fe528a1a85b github.com: https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.23