A vulnerability identified as problematic has been detected in BigBlueButton up to 3.0.18 . The affected element is an unknown function. This manipulation causes cross site scripting. This vulnerability appears as CVE-2026-27737 . The attack may be initiated remotely. There is no available exploit. You should upgrade the affected component.