Authentication Bypass in OpenReception Appointment Booking Software
CVE-2026-48088
What is CVE-2026-48088?
OpenReception's appointment booking software has a serious vulnerability that allows unauthenticated attackers to store maliciously controlled encryption keys without the need for proper authentication. This is possible due to a flaw in the API handler that processes requests to store these keys; it fails to enforce authentication checks correctly. As a result, any attacker can add themselves as an encryption recipient for patient appointments, potentially exposing sensitive appointment payloads. The weakness is compounded by inadequate validation of input parameters, enabling skewed entries that could further disrupt legitimate operations. Users are encouraged to upgrade to version 1.0.4 or later to mitigate this risk.
Affected Version(s)
appointment-booking-software < 1.0.4
