Vulnerability in OpenReception's Appointment Booking Software Affects Login Security
CVE-2026-48084
What is CVE-2026-48084?
OpenReception's appointment booking software, particularly versions before 1.0.2, has a significant security oversight concerning login mechanisms. The system lacks a throttle on failed passphrase login attempts, enabling attackers to unleash unlimited wrong passphrase guesses against any known email address. Despite the presence of a functioning throttle on the WebAuthn challenge endpoint, the passphrase login path does not implement similar measures. This absence exposes user accounts to credential stuffing and dictionary attacks, especially for accounts with weak passphrases. Malicious users could compromise accounts within days on a CPU or even hours using a small GPU farm. The vulnerabilities were addressed in version 1.0.2, which ensures that failed attempts are properly logged and throttled, safeguarding user credentials.
Affected Version(s)
appointment-booking-software < 1.0.2
