CVE-2026-55491 | BigBlueButton up to 3.0.28 index.html.erb meetingName cross site scripting
A vulnerability was found in BigBlueButton up to 3.0.28 and classified as problematic. This impacts an unknown function of the file record-and-playback/screenshare/playback/index.html.erb. Such manipulation of the argument meetingName leads to cross site scripting.
This vulnerability is listed as CVE-2026-55491. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.