PT-2026-41738 · Unknown · Bigbluebutton

Published

2026-05-18

·

Updated

2026-05-19

·

CVE-2026-27737

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 3.0.19
Description Recording playback in presentation format fails to sanitize user input within the public chat. This allows a malicious actor to execute a targeted Cross-Site Scripting (XSS) attack—a technique where malicious scripts are injected into trusted websites—which is triggered for any user replaying the recording.
Recommendations Update to version 3.0.19.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27737

Affected Products

Bigbluebutton