CVE-2026-46404: Bigbluebutton

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23.

Affected products

Published 2026-07-16. Last modified 2026-07-17.