CVE-2026-46404: BigBlueButton: Presentation URL Security Hardening
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BigBlueButtonto a version that resolves this vulnerability.Fixed in 3.0.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46404?
The severity of CVE-2026-46404 is medium with a score of 6.8.
How do I fix CVE-2026-46404?
To fix CVE-2026-46404, update BigBlueButton to version 3.0.23 or later.
What type of vulnerability is CVE-2026-46404?
CVE-2026-46404 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What issue does CVE-2026-46404 address?
CVE-2026-46404 addresses improper restriction of access to site local and link local addresses in BigBlueButton.
When was CVE-2026-46404 published?
CVE-2026-46404 was published on July 16, 2026.