BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available. | |
| Title | BigBlueButton has Open Redirect vulnerability in ApiController | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T16:27:01.507Z
Reserved: 2026-02-23T18:37:14.790Z
Link: CVE-2026-27736
No data.
Status : Received
Published: 2026-02-25T17:25:40.283
Modified: 2026-02-25T17:25:40.283
Link: CVE-2026-27736
No data.
OpenCVE Enrichment
No data.