CVE-2026-71555
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="_blank") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-1022
- Published
- 2026-08-06
- Last modified
- 2026-08-07
Affected products
- THM-Health PILOS
Weakness type
Related vulnerabilities
- CVE-2025-59842 — JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
- CVE-2025-42941 — Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
- CVE-2025-33014 — IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
- CVE-2024-39727 — IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing
- CVE-2018-25089 — glb Meetup Tag Extension Link Attribute reverse tabnabbing
- CVE-2022-4927 — ualbertalib NEOSDiscovery _refworks.html.erb reverse tabnabbing
- CVE-2018-25058 — Twitter-Post-Fetcher Link Target twitterFetcher.js reverse tabnabbing
- CVE-2020-36624 — ahorner text-helpers translation.rb reverse tabnabbing