Improper Handling of Extra Parameters in BigBlueButton - #VU150171
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to insufficient validation and encoding of parameter names when generating signed join URLs. A remote user can inject parameters or duplicate the "checksum" parameter and modify the URL behavior.