User Authentication Vulnerability in OpenReception's Appointment Booking Software
CVE-2026-48087

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48087?

A vulnerability in OpenReception's appointment booking software allows an unauthenticated attacker to exploit the registration handler. By generating a registration response with their own authenticator and submitting it to any victim user's endpoint, the attacker can pass the initial validation. Consequently, this allows unauthorized access to victim accounts, bypassing security protocols, and potentially leading to account takeover. This situation is exacerbated if the attacker knows the victim's email and user ID, making it crucial for maintainers to assess and secure all exposure surfaces. Version 1.0.2 addresses this vulnerability.

Affected Version(s)

appointment-booking-software < 1.0.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.