CVE-2026-46353: BigBlueButton API checksum bypass via presentationUploadExternalUrl
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BigBlueButton (bbb-web)to a version that resolves this vulnerability.Fixed in 3.0.21
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46353?
CVE-2026-46353 has a severity rating of 8.1, classifying it as high risk.
How do I fix CVE-2026-46353?
To fix CVE-2026-46353, upgrade to BigBlueButton version 3.0.21 or later.
What components are affected by CVE-2026-46353?
CVE-2026-46353 affects the bbb-web component of BigBlueButton prior to version 3.0.21.
What impact does CVE-2026-46353 have on user security?
CVE-2026-46353 allows attackers to bypass checksum validation, potentially leading to unauthorized API access.
Is there a known exploit for CVE-2026-46353?
At this time, specific exploits for CVE-2026-46353 have not been publicly disclosed.