CVE-2026-27466 is a Denial of Service vulnerability affecting BigBlueButton versions 3.0.21 and below. It stems from flawed documentation instructing users to expose ClamAV ports to the internet, allowing remote attackers to exhaust server resources or shut down the clamd process. With a CVSS score of 8.2 (HIGH), this vulnerability is easily exploitable remotely with low attack complexity, potentially leading to high availability impact and some confidentiality loss. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has garnered some community discussion. Users are only affected if they followed the specific, optional instructions in the BigBlueButton documentation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.22CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.