Weak Rate Limiting in OpenReception Appointment Booking Software
CVE-2026-48082

3.7LOW

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48082?

The OpenReception appointment booking software employs a SHA-256 proof-of-work mechanism to control the rate at which unauthenticated clients can establish connections and submit appointments. However, prior to version 1.0.6, the difficulty of this proof-of-work challenge was set too low, allowing modern hardware to bypass intended limitations within 200 milliseconds. Attackers could exploit this weakness to flood the booking system with requests, effectively negating any rate-limiting benefits. The issue arises from the ability to supply attacker-controlled parameters during the challenge, enabling them to generate unique throttle keys and evade limitations designed to control booking traffic. The release of version 1.0.6 addresses this vulnerability to enhance the security of the booking process.

Affected Version(s)

appointment-booking-software < 1.0.6

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.