CVE-2026-48076
Published:August 06, 2026
Updated:September 01, 2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: "bootstrap-challenge" (returns a 16-bit PoW challenge with "difficulty=4" leading hex zeroes), "bootstrap-verify" (validates the PoW and issues a Bearer booking access token), and "create-new-client" (consumes the token and creates the tunnel and first appointment). The token correctly binds to "tenantId", "tunnelId", "clientPublicKey", and "emailHash", but never to "channelId". The "bootstrap-challenge" request schema does not even accept a "channelId", and the issued token's payload contains no channel information. Independently, the service function "createNewClientWithAppointment" checks only "channel.archived = false". The "channel.isPublic" check that protects "addAppointmentToTunnel" is missing in the new-client path. The combination means: an attacker completes the bootstrap flow normally (16-bit PoW, completes in well under one second on commodity hardware, no rate limiting beyond the throttle store), receives a valid booking access token, and then submits the "create-new-client" payload with "channelId" pointing to a private ("isPublic = false") channel. The booking lands as "CONFIRMED" if the target channel has "requiresConfirmation = false" (the default), otherwise as "NEW". The patient-facing UI does not list private channels in its picker ("/api/public/channels" correctly filters "isPublic = true"), so the channel ID must be obtained out of band. The companion finding V-10 (schedule endpoint discloses private channels) provides exactly that: a single unauthenticated GET reveals every private channel ID for any tenant. V-10 plus V-11 together make private channels fully reachable to anonymous attackers. As of time of publication, no known patched versions are available.
Related Resources (3)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW
Weakness Type (CWE)
Incorrect Authorization
EPSS
Base Score:
0.24