CVE-2026-46382: Meeting-Room-Booking-System Mrbs-Code
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available.
Affected products
- Meeting-Room-Booking-System Mrbs-Code: before 1.12.2 (fixed in 1.12.2)
Published 2026-08-13. Last modified 2026-09-09.