Escalation of Privileges in OpenReception Appointment Booking Software
CVE-2026-48086
9.9CRITICAL
What is CVE-2026-48086?
OpenReception's appointment booking software previously allowed a tenant administrator to promote themselves to a global administrator via a flawed API handler. The lack of enforced policy checks enabled tenant admins to update their roles incorrectly, thereby gaining unauthorized access to manage every tenant's configuration and users. This misconfiguration posed a significant risk both on hosted services and self-hosted deployments, allowing malicious administrators to execute actions beyond their intended scope. Version 1.0.2 addresses this vulnerability, ensuring that only authorized personnel can grant global administrative privileges.
Affected Version(s)
appointment-booking-software < 1.0.2
