CVE-2026-71555: PILOS: Reverse tabnabbing in room description
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="blank") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PILOS (Platform for Interactive Live-Online Seminars)to a version that resolves this vulnerability.Fixed in 4.14.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71555?
The severity of CVE-2026-71555 is rated as medium with a score of 4.1.
What is the impact of CVE-2026-71555?
CVE-2026-71555 allows for reverse tabnabbing attacks due to the lack of a Cross-Origin-Opener-Policy header.
How do I fix CVE-2026-71555?
To fix CVE-2026-71555, upgrade PILOS to version 4.14.1 or later, which includes the necessary security header.
Which versions of PILOS are affected by CVE-2026-71555?
CVE-2026-71555 affects PILOS versions from 2.1.0 up to 4.14.1.
What type of vulnerability is CVE-2026-71555?
CVE-2026-71555 is categorized as a web security vulnerability involving reverse tabnabbing.