BigBlueButton Audio Leakage Vulnerability When Joining Sessions with Microphone Muted

Vulnerability

A vulnerability in BigBlueButton, an open-source virtual classroom platform, allows audio to be sent to the server from clients joining a session with the microphone muted. This issue exists in versions 3.0.19 and prior. Although the server discards audio from muted streams, it could potentially enable malicious server operators to access this audio data. The problem arises only during the initial connection to the meeting, before the user unmutes the microphone.

Impact

Exploitation of this vulnerability could lead to unauthorized access to audio data from participants, creating a risk of privacy violations.

Reproduction

To reproduce this vulnerability, join a BigBlueButton session using a client version prior to 3.0.20 with the microphone muted. Upon joining, the client will inadvertently send audio to the server, despite the mute status. This audio will not be heard by other participants, but could be accessed by the server operator.

Remediation

Users are advised to upgrade to BigBlueButton version 3.0.20 or later, where this vulnerability has been fixed.

Added: Feb 21, 2026, 8:24 AM
Updated: Feb 21, 2026, 8:24 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
3.9
remediation
8.3
relevance
3.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.