CVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21.
Configurations

No configuration.

History

16 Jul 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 19:16

Updated : 2026-07-17 18:33


NVD link : CVE-2026-46353

Mitre link : CVE-2026-46353

CVE.ORG link : CVE-2026-46353


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control