VYPR
Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026

BigBlueButton API checksum bypass via presentationUploadExternalUrl

CVE-2026-46353

Description

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.