Escalation of Privileges in OpenReception Appointment Booking Software
CVE-2026-48086

9.9CRITICAL

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48086?

OpenReception's appointment booking software previously allowed a tenant administrator to promote themselves to a global administrator via a flawed API handler. The lack of enforced policy checks enabled tenant admins to update their roles incorrectly, thereby gaining unauthorized access to manage every tenant's configuration and users. This misconfiguration posed a significant risk both on hosted services and self-hosted deployments, allowing malicious administrators to execute actions beyond their intended scope. Version 1.0.2 addresses this vulnerability, ensuring that only authorized personnel can grant global administrative privileges.

Affected Version(s)

appointment-booking-software < 1.0.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.