CVE-2026-46688: Meeting-Room-Booking-System Mrbs-Code

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the user to a query-specified location. This allows an attacker to create a specially-crafted URL to an MRBS installation that will cause the user who clicks it to be redirected to the attacker-specified redirect URL, which could be a spoofed MRBS login page, for example. Version 1.12.2 contains a fix. No known workarounds are available.

Affected products

Published 2026-08-13. Last modified 2026-09-09.