Junglewise Threat Intelligence

CVE-2026-48074: OpenReception appointment booking software cross-tenant invite deletion

CVE-2026-48074 · Severity: low · CVSS 2.7 · Published 2026-08-06

Technologies: OpenReception Appointment-Booking-Software. Vendors: OpenReception.

Executive brief

OpenReception is a secure appointment booking platform used to manage staff scheduling and invites across multiple organizations (tenants). A tenant administrator can silently delete pending invitations in other unrelated organizations by deleting a staff member with a matching email address. This can disrupt staff onboarding and enables malicious tenant operators to sabotage competitors or target organizations on the same platform without detection.

Technical details

The vulnerability is a missing tenant isolation (CWE-1308) in the StaffService.deleteStaffMember() function. When a TENANT_ADMIN deletes a staff member, the code runs an invite cleanup query that deletes rows from the user_invite table by email address: `or(eq(userInvite.createdUserId, staffId), eq(userInvite.email, userToDelete.email))`. The email clause lacks a tenantId predicate, allowing deletion of any pending invite across all tenants with a matching email. The user-side delete is correctly scoped to the tenant, making this a side-effect bug. Attack requires TENANT_ADMIN role (low privilege) and network access to the platform API. An attacker can invoke this by deleting any staff member in their controlled tenant whose email matches pending invites in target tenants. The issue is patched in version 1.0.6.

Affected products

  • OpenReception appointment-booking-software <1.0.6

Timeline

  • 2026-08-06: disclosed
  • 2026: patched: Version 1.0.6 includes fix

References

Related threats