Junglewise Threat Intelligence

CVE-2026-48076: OpenReception appointment booking unauthorized channel access

CVE-2026-48076 · Severity: medium · CVSS 6.5 · Published 2026-08-06

Technologies: OpenReception Appointment-Booking-Software. Vendors: OpenReception.

Executive brief

OpenReception's appointment booking platform allows attackers to bypass channel privacy controls and book appointments on private channels without authorization. An attacker can obtain private channel identifiers through an information disclosure vulnerability, then use those IDs to create appointments on restricted channels that should only be accessible to verified patients. This undermines the platform's privacy model and allows unsolicited appointments on channels intended for confidential use.

Technical details

The vulnerability stems from a missing authorization check in the new-client booking flow. The bootstrap token issued by `bootstrap-verify` does not bind to `channelId`, and the `createNewClientWithAppointment` service function only validates `channel.archived = false` but omits the `channel.isPublic` check that exists in other appointment creation paths. An unauthenticated attacker can complete the bootstrap flow (16-bit proof-of-work with no rate limiting), obtain a valid booking token, and then submit a `create-new-client` request with an arbitrary `channelId` pointing to a private channel. Combined with V-10 (information disclosure of private channel IDs via unauthenticated schedule endpoint), this allows complete bypass of channel privacy restrictions. Appointments are created as `CONFIRMED` or `NEW` depending on the target channel's confirmation settings.

Affected products

  • OpenReception appointment booking software 1.0.1 and prior

Timeline

  • 2026-08-06: disclosed: Initial advisory published

Related threats