CVE-2026-27737: BigBlueButton has Stored XSS in bbb-playback replay
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been fixed 3.0.19.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BigBlueButtonto a version that resolves this vulnerability.Fixed in 3.0.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27737?
CVE-2026-27737 is classified as a medium severity vulnerability due to its potential for exploitation via stored XSS.
How do I fix CVE-2026-27737?
To fix CVE-2026-27737, upgrade BigBlueButton to version 3.0.19 or later where the input sanitization issue has been resolved.
What versions of BigBlueButton are affected by CVE-2026-27737?
CVE-2026-27737 affects BigBlueButton versions prior to 3.0.19.
What type of vulnerability is CVE-2026-27737?
CVE-2026-27737 is a stored cross-site scripting (XSS) vulnerability found in BigBlueButton.
Can CVE-2026-27737 be exploited remotely?
Yes, CVE-2026-27737 can be exploited remotely by an attacker leveraging the vulnerability in public chat.