Skip to content
Threat Feed
high advisory

Information Disclosure Vulnerability in BigBlueButton

A vulnerability in BigBlueButton versions prior to 2.7.7 allows a remote, unauthenticated attacker to access sensitive information due to improper data handling.

CVE search metadata

CVE search record: CVE-2024-36127. Severity: high. CVSS: 7.5. EPSS: 0.44%. KEV: no. Product: BigBlueButton (< 2.7.7). Brief: Information Disclosure Vulnerability in BigBlueButton. Brief link: https://feed.craftedsignal.io/briefs/2026-08-bigbluebutton-info-disclosure/

A security vulnerability has been identified in BigBlueButton, a web-based conferencing system, affecting versions prior to 2.7.7. The vulnerability, tracked as CVE-2024-36127, allows a remote, unauthenticated attacker to perform information disclosure. This flaw is rooted in improper handling of sensitive data within the application environment, which potentially exposes confidential information that should be restricted. Organizations using BigBlueButton deployments are advised to update to version 2.7.7 or later to remediate the issue.

Impact

Successful exploitation of this vulnerability enables unauthorized access to sensitive information within the BigBlueButton application environment. This could result in the exposure of meeting details, participant data, or other system-level information depending on the specific data handled by the vulnerable endpoints. The impact is primarily a loss of confidentiality.

Recommendation

  • Upgrade BigBlueButton server installations to version 2.7.7 or later to mitigate CVE-2024-36127.
  • Review server-side logs for unusual patterns of unauthenticated access to sensitive API endpoints or data directory structures following the update process.

Mitigations

Upgrade BigBlueButton to version 2.7.7 or later

immediate IT Operations

CVE-2024-36127