No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 26 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bigbluebutton
Bigbluebutton bigbluebutton |
|
| Vendors & Products |
Bigbluebutton
Bigbluebutton bigbluebutton |
Wed, 25 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available. | |
| Title | BigBlueButton has Open Redirect vulnerability in ApiController | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T21:33:41.504Z
Reserved: 2026-02-23T18:37:14.790Z
Link: CVE-2026-27736
Updated: 2026-02-26T21:07:14.460Z
Status : Awaiting Analysis
Published: 2026-02-25T17:25:40.283
Modified: 2026-02-27T14:06:59.787
Link: CVE-2026-27736
No data.
OpenCVE Enrichment
Updated: 2026-02-26T13:15:21Z