Vulnerability in OpenReception's Appointment Booking Software Affects Login Security
CVE-2026-48084

7.4HIGH

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48084?

OpenReception's appointment booking software, particularly versions before 1.0.2, has a significant security oversight concerning login mechanisms. The system lacks a throttle on failed passphrase login attempts, enabling attackers to unleash unlimited wrong passphrase guesses against any known email address. Despite the presence of a functioning throttle on the WebAuthn challenge endpoint, the passphrase login path does not implement similar measures. This absence exposes user accounts to credential stuffing and dictionary attacks, especially for accounts with weak passphrases. Malicious users could compromise accounts within days on a CPU or even hours using a small GPU farm. The vulnerabilities were addressed in version 1.0.2, which ensures that failed attempts are properly logged and throttled, safeguarding user credentials.

Affected Version(s)

appointment-booking-software < 1.0.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.