# CVE-2026-46351

## Summary

- **CVE ID:** CVE-2026-46351
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-330
- **Published:** Jul 16, 2026
- **Last Modified:** Jul 17, 2026

## Description

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session user to predict other users' conference session tokens and impersonate them. This issue is fixed in version 3.0.21.

## Affected Products

- bigbluebutton — bigbluebutton (< 3.0.21)

## References

- [CNA](https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-7959-pf2v-xc4h)
- [CNA](https://github.com/bigbluebutton/bigbluebutton/commit/8457886c248aeba5597ee8749267602d6d117e98)
- [CNA](https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.21)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.46%
- **EPSS Percentile:** 38.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._