Junglewise Threat Intelligence

CVE-2026-46355: BigBlueButton authentication bypass in API controller

CVE-2026-46355 · Severity: high · CVSS 7.1 · Published 2026-08-20

Technologies: BigBlueButton. Vendors: BigBlueButton.

Executive brief

BigBlueButton is an open-source virtual classroom platform used for online meetings and education. An exposed API endpoint allowed attackers to hijack an existing participant's session and impersonate them in an active meeting without proper authentication, potentially enabling unauthorized access to sensitive meeting content and participant information.

Technical details

The vulnerability exists in BigBlueButton's ApiController.groovy file where the handleJoinExistingUser method was exposed as a routable controller action rather than a private helper method. An attacker able to supply a valid existingUserID for an active meeting participant could reuse that participant's session and gain unauthorized access to the meeting. The vulnerability requires network access to the BigBlueButton API endpoint and knowledge of an active participant's user ID, but does not require authentication. The fix, released in version 3.0.23, makes the vulnerable controller helper methods private to prevent direct routing.

Affected products

  • BigBlueButton BigBlueButton prior to 3.0.23

Timeline

  • 2026-08-20: disclosed
  • 2026-03-16: patched: Fixed in version 3.0.23

References

Related threats