CVE-2020-26163: Bigbluebutton Greenlight
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
Affected products
- Bigbluebutton Greenlight: before 2.5.6 (fixed in 2.5.6)
Published 2020-09-30. Last modified 2026-06-17.