PT-2026-21365 · Unknown · Bigbluebutton

Jörg Schwenk

+3

·

Published

2026-02-21

·

Updated

2026-02-21

·

CVE-2026-27467

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions 3.0.19 and below
Description BigBlueButton is a virtual classroom platform. When a user joins a session with the microphone initially muted, the client may send audio data to the server despite the mute state. While the server discards this audio, preventing it from being audible to other participants, a malicious server operator could potentially access this data. This behavior occurs only between joining the meeting and the first time the user unmutes.
Recommendations Update to version 3.0.20 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-27467
GHSA-6GJ9-5RHM-68J8

Affected Products

Bigbluebutton