PatchSiren

bigbluebutton CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM bigbluebutton CVE published 2026-08-20

CVE-2026-55491

CVE-2026-55491 is a medium-severity vulnerability in BigBlueButton, an open-source virtual classroom. A low-privileged user could store a crafted meeting name that embedded script content, which would execute in another user's browser when replaying a recording. This issue was fixed in version 3.0.29. The vulnerability allows low-privileged users to inject script content into meeting names, potentially le [truncated]

MEDIUM bigbluebutton CVE published 2026-08-20

CVE-2026-55489

CVE-2026-55489 is a medium-severity vulnerability in BigBlueButton, an open-source virtual classroom. The issue allows presenters to delete presentations from other meetings by submitting a presentationId through /api/graphql. This can disrupt the availability of the presentation in the other meeting. The vulnerability is caused by a lack of verification of the presentation's meeting identifier before del [truncated]

HIGH bigbluebutton CVE published 2026-08-20

CVE-2026-46682

CVE-2026-46682 is a high-severity vulnerability in BigBlueButton, an open-source virtual classroom. Authenticated moderators can inject SQL through meetingId and userId values, allowing arbitrary SQL execution against the application database. This issue is fixed in version 3.0.23. The vulnerability allows for potential unauthorized database access and modification, posing a risk of data breaches and unau [truncated]

HIGH bigbluebutton CVE published 2026-08-20

CVE-2026-46355

CVE-2026-46355 debrief based on CVE Program and NVD records. BigBlueButton versions prior to 3.0.23 exposed the /bigbluebutton/api/handleJoinExistingUser endpoint, allowing an attacker to impersonate an existing participant in a meeting. This issue is fixed in version 3.0.23. Defenders managing BigBlueButton deployments, especially those with exposed API endpoints, should assess their exposure and verify [truncated]

MEDIUM bigbluebutton CVE published 2026-07-16

CVE-2026-46404

CVE-2026-46404 is a vulnerability in BigBlueButton, an open-source virtual classroom. Prior to version 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The issue has been fixed in version 3.0.23. This vulnerability could allow unauthorized access to presentation content. Users of BigBlueButton should review their deployment and update to the [truncated]

HIGH bigbluebutton CVE published 2026-07-16

CVE-2026-46353

CVE-2026-46353 is a security vulnerability in BigBlueButton, an open-source virtual classroom. The issue allows users to bypass checksum validation when a presentationUploadExternalUrl parameter is supplied to API request handling. This problem was addressed in version 3.0.21. Affected product deployments should be identified and patched to prevent potential security bypass. The vulnerability has a high C [truncated]

HIGH bigbluebutton CVE published 2026-07-16

CVE-2026-46351

CVE-2026-46351: BigBlueButton Insufficiently Secure Randomness. The CVE record was published on 2026-07-16T19:16:45.863Z and has not been modified since then. This vulnerability affects BigBlueButton, an open-source virtual classroom, and allows a session user to predict other users' conference session tokens and impersonate them due to insufficiently secure randomness in session token generation. The iss [truncated]

MEDIUM BigBlueButton CVE published 2026-05-18

CVE-2026-27737

A stored cross-site scripting (XSS) vulnerability exists in BigBlueButton's recording playback feature (presentation format) prior to version 3.0.19. The public chat messages displayed during recording playback were not properly sanitized, allowing a malicious actor to inject and execute arbitrary JavaScript when any user replays an affected recording. The vulnerability requires low privileges to exploit [truncated]