User Authentication Vulnerability in OpenReception's Appointment Booking Software
CVE-2026-48087
9.8CRITICAL
What is CVE-2026-48087?
A vulnerability in OpenReception's appointment booking software allows an unauthenticated attacker to exploit the registration handler. By generating a registration response with their own authenticator and submitting it to any victim user's endpoint, the attacker can pass the initial validation. Consequently, this allows unauthorized access to victim accounts, bypassing security protocols, and potentially leading to account takeover. This situation is exacerbated if the attacker knows the victim's email and user ID, making it crucial for maintainers to assess and secure all exposure surfaces. Version 1.0.2 addresses this vulnerability.
Affected Version(s)
appointment-booking-software < 1.0.2
