CVE-2026-41126: BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41126?
CVE-2026-41126 has been classified as a moderate severity Open Redirect vulnerability.
How do I fix CVE-2026-41126?
To fix CVE-2026-41126, upgrade BigBlueButton to version 3.0.24 or later.
What versions of BigBlueButton are affected by CVE-2026-41126?
BigBlueButton versions prior to 3.0.24 are affected by CVE-2026-41126.
What is the impact of CVE-2026-41126?
The impact of CVE-2026-41126 is that it allows attackers to perform Open Redirect attacks through manipulated logout URLs.
How can I determine if my system is vulnerable to CVE-2026-41126?
You can determine if your system is vulnerable to CVE-2026-41126 by checking if you are using a version of BigBlueButton earlier than 3.0.24.