CVE-2026-41127
MEDIUMBigBlueButton's missing authorization allows viewer to inject/overwrite captions
Title source: cnaDescription
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
6.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
bigbluebutton/bigbluebutton
< 3.0.24
Published
Apr 22, 2026
Tracked Since
Apr 22, 2026