Appointment Booking Software Vulnerability in OpenReception
CVE-2026-48076

6.5MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48076?

OpenReception's appointment booking software has a significant access control vulnerability in its new-client booking flow. The software issues booking access tokens that do not properly validate the channelId, allowing attackers to generate valid tokens for private channels. The lack of constraints means an attacker can exploit this by obtaining channel IDs via a separate unauthenticated endpoint. As a result, they can create bookings in private channels without proper authorization. This oversight could lead to serious confidentiality issues, exposing sensitive information to unauthorized individuals.

Affected Version(s)

appointment-booking-software <= 1.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.