CVE-2026-46688: Meeting Room Booking System has an unauthenticated open redirect
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the user to a query-specified location. This allows an attacker to create a specially-crafted URL to an MRBS installation that will cause the user who clicks it to be redirected to the attacker-specified redirect URL, which could be a spoofed MRBS login page, for example. Version 1.12.2 contains a fix. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Meeting Room Booking System (MRBS)to a version that resolves this vulnerability.Fixed in 1.12.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46688?
CVE-2026-46688 has a risk rating of 30, indicating a significant security concern.
How do I fix CVE-2026-46688?
To fix CVE-2026-46688, update your Meeting Room Booking System to version 1.12.2 or later.
What type of vulnerability is CVE-2026-46688?
CVE-2026-46688 is an unauthenticated open redirect vulnerability in the Meeting Room Booking System.
What impact does CVE-2026-46688 have?
CVE-2026-46688 allows attackers to redirect users to malicious locations via specially-crafted URLs.
Who is affected by CVE-2026-46688?
All users of the Meeting Room Booking System prior to version 1.12.2 are affected by CVE-2026-46688.