The BigBlueButton software had a security vulnerability that allowed unauthorized users to inject or overwrite captions in virtual classrooms before version 3.0.24.
Claims
The BigBlueButton software had a security vulnerability that allowed unauthorized users to inject or overwrite captions in virtual classrooms before version 3.0.24.
Parent: Software SecurityEntity: BigBlueButtonImpact: negativeDate: Apr 22, 2026Target: The security of BigBlueButton software
The BigBlueButton software had an open redirect vulnerability that could be exploited through the join API before version 3.0.24.
Parent: Software SecurityEntity: BigBlueButtonImpact: negativeDate: Apr 22, 2026Target: The security of BigBlueButton software
Source posts
๐จ EUVD-2026-24563
๐ Score: 4.3/10 (CVSS v3.1)
๐ฆ Product: bigbluebutton
๐ข Vendor: bigbluebutton
๐
Updated: 2026-04-21
๐ BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that t...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24563
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24565
๐ Score: 6.5/10 (CVSS v3.1)
๐ฆ Product: bigbluebutton
๐ข Vendor: bigbluebutton
๐
Updated: 2026-04-21
๐ BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workaro...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24565
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability