#VU125910 Improper access control in BigBlueButton - CVE-2024-38518
Published: June 27, 2024 / Updated: April 14, 2026
BigBlueButton
Blindside Networks
Description
The vulnerability allows a remote user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to improper access control in the join API when handling additional parameters in join requests. A remote user can supply a crafted join link with additional parameters to disclose sensitive information and cause a denial of service.
User interaction is required because the issue involves use of a valid join link to a meeting.