Appointment Booking Software Vulnerability in OpenReception
CVE-2026-48071
What is CVE-2026-48071?
The appointment booking software by OpenReception is susceptible to a design flaw in its PIN-type challenge throttle mechanism. Before version 1.0.4, the system utilized a shared emailHash across all tenants, which allowed attackers to exploit the challenge and lock out users on one tenant by triggering failed responses on another. This vulnerability can lead to a sustained denial of service, as repeated failed authentication attempts against a specific email can increase lockout durations significantly, ranging from 60 seconds to up to an hour. Affected patients may find themselves locked out of their accounts without any direct connection to the attacker. OpenReception has since released version 1.0.4, which addresses this critical issue.
Affected Version(s)
appointment-booking-software < 1.0.4
