PT-2026-21960 · Unknown · Bigbluebutton

Denizparlak

·

Published

2026-02-25

·

Updated

2026-03-05

·

CVE-2026-27736

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 3.0.20
Description BigBlueButton is a virtual classroom platform. Versions of the 3.x branch before 3.0.20 contain an Open Redirect issue. The errorRedirectUrl string is not properly validated, and is directly used in the respondWithRedirect function. This allows for redirection to a malicious URL.
Recommendations Update to version 3.0.20 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-27736
GHSA-65CV-RG9F-QQRX

Affected Products

Bigbluebutton