PatchSiren

bigbluebutton CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM bigbluebutton CVE published 2026-08-20

CVE-2026-55491

BigBlueButton is an open-source virtual classroom. A vulnerability in BigBlueButton versions prior to 3.0.29 allows a low-privileged user to store a crafted meeting name that embedded script content. When another user replays the recording, the script executes in their browser. The issue is fixed in version 3.0.29. Users should review and update their installations to prevent potential script execution vi [truncated]

MEDIUM bigbluebutton CVE published 2026-08-20

CVE-2026-55489

BigBlueButton is an open-source virtual classroom. A vulnerability in BigBlueButton allowed presenters to submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. The akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala file did not verify the presentation's meeting identifier before deletion, allowing [truncated]

HIGH bigbluebutton CVE published 2026-08-20

CVE-2026-46682

Authenticated moderators in BigBlueButton versions before 3.0.23 could inject SQL via meetingId and userId in refreshBreakoutRoomsVisibleForUsers. The issue is fixed in version 3.0.23. This SQL injection vulnerability allows authenticated moderators to execute arbitrary SQL queries against the application database, potentially leading to data breaches or system compromise. BigBlueButton users and administ [truncated]

MEDIUM bigbluebutton CVE published 2026-07-16

CVE-2026-46404

CVE-2026-46404 is a vulnerability in BigBlueButton, an open-source virtual classroom. Prior to version 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The issue has been fixed in version 3.0.23. This vulnerability could allow unauthorized access to presentation content. Users of BigBlueButton should review their deployment and update to the [truncated]

HIGH bigbluebutton CVE published 2026-07-16

CVE-2026-46353

CVE-2026-46353 is a security vulnerability in BigBlueButton, an open-source virtual classroom. The issue allows users to bypass checksum validation when a presentationUploadExternalUrl parameter is supplied to API request handling. This problem was addressed in version 3.0.21. Affected product deployments should be identified and patched to prevent potential security bypass. The vulnerability has a high C [truncated]

HIGH bigbluebutton CVE published 2026-07-16

CVE-2026-46351

CVE-2026-46351: BigBlueButton Insufficiently Secure Randomness. The CVE record was published on 2026-07-16T19:16:45.863Z and has not been modified since then. This vulnerability affects BigBlueButton, an open-source virtual classroom, and allows a session user to predict other users' conference session tokens and impersonate them due to insufficiently secure randomness in session token generation. The iss [truncated]

MEDIUM BigBlueButton CVE published 2026-05-18

CVE-2026-27737

A stored cross-site scripting (XSS) vulnerability exists in BigBlueButton's recording playback feature (presentation format) prior to version 3.0.19. The public chat messages displayed during recording playback were not properly sanitized, allowing a malicious actor to inject and execute arbitrary JavaScript when any user replays an affected recording. The vulnerability requires low privileges to exploit [truncated]