CVE-2020-26163: Bigbluebutton Greenlight

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.

Affected products

Published 2020-09-30. Last modified 2026-06-17.