BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session user to predict other users' conference session tokens and impersonate them. This issue is fixed in version 3.0.21.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46351.json",
"cwe_ids": [
"CWE-330"
],
"cna_assigner": "GitHub_M"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.0.21"
}
]
}
[
{
"id": "CVE-2026-46351-eb901e84",
"target": {
"file": "bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"107816761300497150788251538289818199915",
"319022996089098753387531060019535594610",
"283060141379493212096909851039163446183",
"316656843430815293078634585412341161858",
"336291095491640805804695097310050733012",
"289916862819442160213376416766296423402",
"137001160105945224794820402543128672165",
"223163553707596551023648335031104551541",
"275970060005458604864282566590708687784"
]
},
"signature_version": "v1",
"source": "https://github.com/bigbluebutton/bigbluebutton/commit/8457886c248aeba5597ee8749267602d6d117e98",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46351.json"
"2026-08-12T16:09:38Z"