BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.
References
Configurations
No configuration.
History
22 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 00:16
Updated : 2026-04-22 20:26
NVD link : CVE-2026-41127
Mitre link : CVE-2026-41127
CVE.ORG link : CVE-2026-41127
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
