CSRF Vulnerability in PILOS Affecting BigBlueButton
CVE-2026-22800
2.4LOW
What is CVE-2026-22800?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrative API endpoint of PILOS, which is a frontend for BigBlueButton. This vulnerability allows authenticated users to unintentionally terminate all active video conferences on the server. The affected endpoint, while protected by authorization checks, is accessible via HTTP GET request, enabling implicit invocations through same-site content such as embedded resources. As a result, an authenticated administrator viewing specially crafted content could unknowingly trigger the termination of all video conferences without explicit intention or confirmation. The issue has been addressed in version 4.10.0.
Affected Version(s)
PILOS < 4.10.0
