Appointment Booking Software Vulnerability in OpenReception
CVE-2026-48076
6.5MEDIUM
What is CVE-2026-48076?
OpenReception's appointment booking software has a significant access control vulnerability in its new-client booking flow. The software issues booking access tokens that do not properly validate the channelId, allowing attackers to generate valid tokens for private channels. The lack of constraints means an attacker can exploit this by obtaining channel IDs via a separate unauthenticated endpoint. As a result, they can create bookings in private channels without proper authorization. This oversight could lead to serious confidentiality issues, exposing sensitive information to unauthorized individuals.
Affected Version(s)
appointment-booking-software <= 1.0.1
