Loading
Generated remediation guidance and an executive summary. No account required.
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.
Cite this page
CVE-2022-26497. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-26497
Use CWE-79, Bigbluebutton vendor hub and Greenlight product page to widen CVE-2022-26497 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-36029, CVE-2022-36028 and CVE-2020-26163 for nearby disclosures in the same product family.