Authentication Flaw in OpenReception's Appointment Booking Software
CVE-2026-48075
What is CVE-2026-48075?
OpenReception's appointment booking software prior to version 1.0.5 is susceptible to an authentication bypass vulnerability. The add-to-tunnel endpoint allows attackers to create appointment entries in any client tunnel without proper caller authentication. By supplying a valid tunnelId and emailHash, attackers can insert appointments with their own specified parameters, resulting in unauthorized access and manipulation of appointment data. The lack of session validation and adequate authorization checks means that the API endpoint is easily exploitable, allowing arbitrary appointment modifications across client tunnels. The vulnerability exists due to design flaws in endpoint access controls, highlighting the importance of robust authentication measures in API security.
Affected Version(s)
appointment-booking-software < 1.0.5
