CVE-2026-46382: Meeting-Room-Booking-System Mrbs-Code

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available.

Affected products

Published 2026-08-13. Last modified 2026-09-09.