Junglewise Threat Intelligence

CVE-2026-3321: ON24 Q&A Chat authorization bypass in console-survey API

CVE-2026-3321 · Severity: info · CVSS 8.7 · Published 2026-03-30

Executive brief

A security flaw in the ON24 engagement platform's Q&A chat feature allows unauthorized individuals to access private conversation histories. By manipulating web addresses, an attacker can view sensitive information such as private messages, internal links, and confidential references intended only for authenticated users. This exposure could lead to the theft of corporate data or provide a foothold for further attacks against internal company systems.

Technical details

The vulnerability is classified as an Insecure Direct Object Reference (IDOR) or Authorization Bypass through User-Controlled Key (CWE-639) within the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. An unauthenticated remote attacker can exploit this by enumerating {EVENTID} and {TIMESTAMP} values to retrieve the complete Q&A history of various events. The leaked data includes private URLs, internal references, and chat messages. This information disclosure can be leveraged for reconnaissance or lateral movement within the victim's environment. As of the advisory date, no official patch or solution has been reported.

Affected products

  • ON24 Q&A Chat

Timeline

  • 2026-03-30: disclosed: Vulnerability discovered by Samuel de Lucas Maroto and coordinated by INCIBE.
  • 2026-03-30: advisory

References