PT-2026-21960 · Unknown · Bigbluebutton

·

CVE-2026-27736

·

Published

2026-02-25

·

Updated

2026-03-05

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 3.0.20
Description BigBlueButton is a virtual classroom platform. Versions of the 3.x branch before 3.0.20 contain an Open Redirect issue. The errorRedirectUrl string is not properly validated, and is directly used in the respondWithRedirect function. This allows for redirection to a malicious URL.
Recommendations Update to version 3.0.20 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27736
GHSA-65CV-RG9F-QQRX

Affected Products

Bigbluebutton