SB2026091624 - Multiple vulnerabilities in BigBlueButton



SB2026091624 - Multiple vulnerabilities in BigBlueButton

Published: September 16, 2026

Security Bulletin ID SB2026091624
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to insecure direct object reference (IDOR) issue.A remote user in one meeting can perform actions in another meeting.


2) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to missing authorization checks when joining a voice bridge. A remote user can join the audio bridge of another meeting, allowing them to listen to and speak in the meeting.


3) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to improper enforcement of plugin role restrictions on custom chat messages. A remote user can publish custom plugin chat messages reserved for moderators, leading to unauthorized content injection.


4) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to improper authorization of presentation uploads. A remote user can upload and convert a presentation into another meeting's presentation namespace to bypass meeting isolation.


5) Improper Handling of Extra Parameters (CVE-ID: N/A)

CWE-ID: CWE-235 - Improper Handling of Extra Parameters

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to insufficient validation and encoding of parameter names when generating signed join URLs. A remote user can inject parameters or duplicate the "checksum" parameter and modify the URL behavior.


Remediation

Install update from vendor's website.