Authentication Bypass in OpenReception Appointment Booking Software
CVE-2026-48088

9.4CRITICAL

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48088?

OpenReception's appointment booking software has a serious vulnerability that allows unauthenticated attackers to store maliciously controlled encryption keys without the need for proper authentication. This is possible due to a flaw in the API handler that processes requests to store these keys; it fails to enforce authentication checks correctly. As a result, any attacker can add themselves as an encryption recipient for patient appointments, potentially exposing sensitive appointment payloads. The weakness is compounded by inadequate validation of input parameters, enabling skewed entries that could further disrupt legitimate operations. Users are encouraged to upgrade to version 1.0.4 or later to mitigate this risk.

Affected Version(s)

appointment-booking-software < 1.0.4

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.