Threat Intel

v0.1

← CVEs

CVE-2026-27736

MED 6.1
Published
2026-02-25
Last Modified
2026-03-05
Affected Apps
1
Affected Devices
4
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available.
Affected Applications in Environment 1
Blue v1.0
4 devices
References 2