CVE-2020-27609: Bigbluebutton
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
Affected products
- Bigbluebutton Bigbluebutton: up to and including 2.2.28
Published 2020-10-21. Last modified 2026-06-17.