Appointment Booking Software Vulnerability in OpenReception
CVE-2026-48071

5.8MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48071?

The appointment booking software by OpenReception is susceptible to a design flaw in its PIN-type challenge throttle mechanism. Before version 1.0.4, the system utilized a shared emailHash across all tenants, which allowed attackers to exploit the challenge and lock out users on one tenant by triggering failed responses on another. This vulnerability can lead to a sustained denial of service, as repeated failed authentication attempts against a specific email can increase lockout durations significantly, ranging from 60 seconds to up to an hour. Affected patients may find themselves locked out of their accounts without any direct connection to the attacker. OpenReception has since released version 1.0.4, which addresses this critical issue.

Affected Version(s)

appointment-booking-software < 1.0.4

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.