Improper access control in BigBlueButton - CVE-2022-29234
Published: June 1, 2022 / Updated: May 14, 2026
BigBlueButton
Detailed vulnerability description
The vulnerability allows a remote user to bypass chat lock restrictions.
The vulnerability exists due to improper access control in public/private chat lock enforcement when lock settings are changed during a meeting. A remote user can send messages within the 5-second grace period to bypass chat lock restrictions.
The issue affects participants in the meeting and is limited to a 5-second window after a lock setting change.