Authentication Flaw in OpenReception's Appointment Booking Software
CVE-2026-48075

6.5MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48075?

OpenReception's appointment booking software prior to version 1.0.5 is susceptible to an authentication bypass vulnerability. The add-to-tunnel endpoint allows attackers to create appointment entries in any client tunnel without proper caller authentication. By supplying a valid tunnelId and emailHash, attackers can insert appointments with their own specified parameters, resulting in unauthorized access and manipulation of appointment data. The lack of session validation and adequate authorization checks means that the API endpoint is easily exploitable, allowing arbitrary appointment modifications across client tunnels. The vulnerability exists due to design flaws in endpoint access controls, highlighting the importance of robust authentication measures in API security.

Affected Version(s)

appointment-booking-software < 1.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.