Junglewise Threat Intelligence

CVE-2026-46404: BigBlueButton SSRF in presentation URL validation

CVE-2026-46404 · Severity: medium · CVSS 6.8 · Published 2026-07-16

Technologies: BigBlueButton. Vendors: BigBlueButton.

Executive brief

BigBlueButton is an open-source virtual classroom platform used for online learning and meetings. A security flaw in how the system handles presentation URLs could allow an authorized user with high-level privileges to access sensitive internal data or services that are normally restricted to the local network. This could lead to the exposure of private internal information, though it requires the attacker to already have administrative or high-level access to the platform.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in BigBlueButton's 'bbb-web' component due to insufficient validation of presentation URLs. Prior to version 3.0.23, the application failed to restrict requests to site-local and link-local IP addresses, and did not properly validate the destination of HTTP redirects. An attacker with high privileges (PR:H) can provide a malicious URL that forces the server to make requests to internal network resources. The vulnerability has been mitigated by pinning resolved IP addresses during redirect following and implementing stricter address validation. Users should upgrade to BigBlueButton 3.0.23 or later.

Affected products

  • BigBlueButton BigBlueButton < 3.0.23

Timeline

  • 2026-05-13: advisory: Original GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD publication date
  • 2026-07-16: patched: Fix confirmed in version 3.0.23

References

Related threats