Security Advisory

CVE-2026-41126

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-21 23:22:34
Last updated 2026-04-22 14:16:24
Assigner GitHub_M
State PUBLISHED

Description

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available.