PT-2026-21365 · Unknown · Bigbluebutton

Jörg Schwenk

+3

·

Publicado

2026-02-21

·

Atualizado

2026-02-21

·

CVE-2026-27467

CVSS v3.1

2.4

Baixa

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions 3.0.19 and below
Description BigBlueButton is a virtual classroom platform. When a user joins a session with the microphone initially muted, the client may send audio data to the server despite the mute state. While the server discards this audio, preventing it from being audible to other participants, a malicious server operator could potentially access this data. This behavior occurs only between joining the meeting and the first time the user unmutes.
Recommendations Update to version 3.0.20 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27467
GHSA-6GJ9-5RHM-68J8

Produtos afetados

Bigbluebutton