Cross-Tenant Information Disclosure in OpenReception's Appointment Booking Software
CVE-2026-48074
2.7LOW
What is CVE-2026-48074?
In OpenReception's appointment booking software, prior to version 1.0.6, a vulnerability allows a TENANT_ADMIN to inadvertently delete a pending user invite in another tenant when deleting a staff member with the same email address. Specifically, the StaffService.deleteStaffMember() function runs an invite cleanup without properly scoping the deletion to the appropriate tenant. This flaw exposes data integrity issues, as it allows unintended consequences across different tenants, resulting in the potential loss of crucial invite data. Update to version 1.0.6 or later to mitigate this risk.
Affected Version(s)
appointment-booking-software < 1.0.6
