CVE-2026-46682 | BigBlueButton up to 3.0.22 Breakout Room User DAO BreakoutRoomUserDAO.scala refreshBreakoutRoomsVisibleForUsers meetingId/userId sql injection
A vulnerability has been found in BigBlueButton up to 3.0.22 and classified as problematic. This affects the function refreshBreakoutRoomsVisibleForUsers of the file akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala of the component Breakout Room User DAO. This manipulation of the argument meetingId/userId causes sql injection.
This vulnerability is tracked as CVE-2026-46682. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.