CVE-2026-41127: BigBlueButton's missing authorization allows viewer to inject/overwrite captions
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41127?
CVE-2026-41127 is rated as a moderate vulnerability due to missing authorization allowing caption injection.
How do I fix CVE-2026-41127?
To fix CVE-2026-41127, update BigBlueButton to version 3.0.24 or later to tighten permissions on caption submissions.
What versions of BigBlueButton are affected by CVE-2026-41127?
CVE-2026-41127 affects all versions of BigBlueButton prior to 3.0.24.
What impact does CVE-2026-41127 have on BigBlueButton users?
CVE-2026-41127 allows unauthorized viewers to inject or overwrite captions during sessions, potentially disrupting communication.
Is there a workaround for CVE-2026-41127 if I can't update immediately?
There is no official workaround for CVE-2026-41127, so updating to the latest version is strongly recommended.