CVE-2026-27737Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been fixed 3.0.19.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-19)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-18: 1Mentions · 2026-05-19: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 205-1805-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-05-192
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27737 BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public… https://www.cve.org/CVERecord?id=CVE-2026-27737 ----- Traducción: CVE-2026-27737 Big… http://infoflow.cloud`

    Post summary

    CVE-2026-27737 exposes unsanitized user input in BigBlueButton's recording playback, potentially allowing injection attacks. The statement merely reports the issue, with no PoC, exploit, or remediation described.

    0000040
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27737 BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public… https://www.cve.org/CVERecord?id=CVE-2026-27737

    Post summary

    The tweet announces a vulnerability in BigBlueButton 3.0.18 and earlier where the recording playback doesn’t sanitize user input, without providing PoC, exploit, or patch information.

    00000186
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27737 Cross-Site Scripting in BigBlueButton Recording Playback ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27737 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-27737, a cross‑site scripting flaw in BigBlueButton's recording playback feature, and provides a link to a vulnerability details page but offers no PoC, exploit code, or patch information.

    0000057
    4.0K followersView on X

Explore more