CVE-2026-41127
EUVD-2026-2456522.04.2026, 00:16
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bigbluebutton | bigbluebutton | 𝑥 < 3.0.24 | CNA |
Common Weakness Enumeration