Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bigbluebutton
Bigbluebutton bigbluebutton |
|
| Vendors & Products |
Bigbluebutton
Bigbluebutton bigbluebutton |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available. | |
| Title | BigBlueButton's missing authorization allows viewer to inject/overwrite captions | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T13:12:52.166Z
Reserved: 2026-04-17T12:59:15.737Z
Link: CVE-2026-41127
Updated: 2026-04-22T13:12:48.269Z
Status : Deferred
Published: 2026-04-22T00:16:28.463
Modified: 2026-04-22T20:26:20.563
Link: CVE-2026-41127
No data.
OpenCVE Enrichment
Updated: 2026-04-22T06:15:10Z