High [CVE-2026-46382] Server-Side Request Forgery in import functionality
This high-severity Red Hat Linux advisory covers CVE-2026-46382.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks.
Version 1.12.2 contains a fix. No known workarounds are available.
This vulnerability, known as Server-Side Request Forgery (SSRF), allows a remote attacker to trick the server into making requests to internal or local network resources. By exploiting this, an attacker could potentially gain unauthorized access to sensitive information or perform actions on behalf of the server.
This Important flaw in the Meeting Room Booking System (MRBS) import functionality allows a remote attacker to perform Server-Side Request Forgery (SSRF). This enables the server to fetch private or local network URIs without proper validation, potentially leading to unauthorized information disclosure or access to internal network services.
The impact is elevated due to the potential for internal network reconnaissance and interaction. This component is shipped only in Fedora.
Red Hat does not ship this component in any core Red Hat products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Weakness: CWE-918.
- < 1.12.2
Official advisory · high-confidence parse· fetched 28 days ago·verify at source
Mitigation checklist
- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Version 1.12.2 contains the fix.
Official advisory · high-confidence parse· fetched 28 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.