Denial of Service Vulnerability in BigBlueButton by Blindside Networks
CVE-2026-27466

7.2HIGH

Key Information:

Vendor
CVE Published:
21 February 2026

What is CVE-2026-27466?

A vulnerability exists in BigBlueButton versions 3.0.21 and earlier, where improper instructions in the Server Customization documentation lead to potential Denial of Service. Exposing the ports 3310 and 7357 makes the server susceptible to attack, allowing remote attackers to overload the server with complex documents or disrupt the clamd process. The issue arises from Docker's networking behavior, which circumvents the protections of Ubuntu's firewall (ufw). Furthermore, the configuration grants write access to sensitive directory mounts, raising concerns about potential future exploits targeting files in that location. This vulnerability is addressed in version 3.0.22, highlighting the importance of keeping software updated.

Affected Version(s)

bigbluebutton < 3.0.22

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.