CSRF Vulnerability in PILOS Affecting BigBlueButton
CVE-2026-22800

2.4LOW

Key Information:

Vendor

Thm-health

Status
Vendor
CVE Published:
12 January 2026

What is CVE-2026-22800?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrative API endpoint of PILOS, which is a frontend for BigBlueButton. This vulnerability allows authenticated users to unintentionally terminate all active video conferences on the server. The affected endpoint, while protected by authorization checks, is accessible via HTTP GET request, enabling implicit invocations through same-site content such as embedded resources. As a result, an authenticated administrator viewing specially crafted content could unknowingly trigger the termination of all video conferences without explicit intention or confirmation. The issue has been addressed in version 4.10.0.

Affected Version(s)

PILOS < 4.10.0

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.