CVE-2026-41126

MEDIUM

BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"

Title source: cna
STIX 2.1

Description

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
bigbluebutton/bigbluebutton < 3.0.24
Published Apr 22, 2026
Tracked Since Apr 22, 2026