โ† All reports

The BigBlueButton software had a security vulnerability that allowed unauthorized users to inject or overwrite captions in virtual classrooms before version 3.0.24.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the BigBlueButton open-source virtual classroom software, both of which were addressed in version 3.0.24. These vulnerabilities relate to unauthorized caption injection and an open redirect issue, highlighting the importance of software updates for security.

Claims

The BigBlueButton software had a security vulnerability that allowed unauthorized users to inject or overwrite captions in virtual classrooms before version 3.0.24.
Parent: Software SecurityEntity: BigBlueButtonImpact: negativeDate: Apr 22, 2026Target: The security of BigBlueButton software
The BigBlueButton software had an open redirect vulnerability that could be exploited through the join API before version 3.0.24.
Parent: Software SecurityEntity: BigBlueButtonImpact: negativeDate: Apr 22, 2026Target: The security of BigBlueButton software

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24563 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: bigbluebutton ๐Ÿข Vendor: bigbluebutton ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that t... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24563 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24565 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: bigbluebutton ๐Ÿข Vendor: bigbluebutton ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workaro... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24565 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability