CVE-2026-46688 is a medium-severity vulnerability in the Meeting Room Booking System (MRBS) that allows unauthenticated redirects to attacker-specified URLs, potentially leading to phishing attacks. The vulnerability was published on 2026-08-13 and last modified on 2026-09-09. Version 1.12.2 contains a fix. Defenders should assess exposure and prioritize upgrading to version 1.12.2 or later, considering p [truncated]
HIGHmeeting-room-booking-systemCVE published 2026-08-13
The Meeting Room Booking System (MRBS) is vulnerable to a security issue where a user-supplied private/local URI can be fetched without checks, potentially allowing for Server-Side Request Forgery (SSRF) attacks. This issue was fixed in version 1.12.2. Defenders should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls.