PatchSiren

meeting-room-booking-system CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM meeting-room-booking-system CVE published 2026-08-13

CVE-2026-46688

CVE-2026-46688 is a medium-severity vulnerability in the Meeting Room Booking System (MRBS) that allows unauthenticated redirects to attacker-specified URLs, potentially leading to phishing attacks. The vulnerability was published on 2026-08-13 and last modified on 2026-09-09. Version 1.12.2 contains a fix. Defenders should assess exposure and prioritize upgrading to version 1.12.2 or later, considering p [truncated]

HIGH meeting-room-booking-system CVE published 2026-08-13

CVE-2026-46382

The Meeting Room Booking System (MRBS) is vulnerable to a security issue where a user-supplied private/local URI can be fetched without checks, potentially allowing for Server-Side Request Forgery (SSRF) attacks. This issue was fixed in version 1.12.2. Defenders should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls.