Junglewise Threat Intelligence

CVE-2026-48082: OpenReception appointment booking software weak proof-of-work in bootstrap challenge

CVE-2026-48082 · Severity: low · CVSS 3.7 · Published 2026-08-06

Technologies: OpenReception Appointment-Booking-Software. Vendors: OpenReception.

Executive brief

OpenReception is appointment booking software used by healthcare providers to manage patient scheduling. The software uses a proof-of-work challenge to rate-limit unauthenticated booking requests, but the difficulty is set too low (16 bits), solvable in under 200 milliseconds on commodity hardware. An attacker can bypass the rate-limiting mechanism and rapidly submit malicious booking requests or poison cryptographic credentials at scale.

Technical details

The bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` implements a SHA-256 proof-of-work mechanism with a hardcoded difficulty of 4 hex zeros (16 bits), intended to rate-limit unauthenticated clients. However, modern hardware solves this challenge in under 200 milliseconds using unoptimized code, providing negligible friction. Additionally, the throttle check uses attacker-controlled parameters (tunnelId, clientPublicKey, emailHash) to generate throttle keys, allowing an attacker to bypass per-binding rate-limiting by supplying fresh values on each request. An attacker can rapidly generate bootstrap challenges and solve them without meaningful server-side friction, enabling bulk abuse of the appointment booking flow and amplification of credential poisoning attacks. Version 1.0.6 increases the difficulty to 5 hex zeros; a more comprehensive fix should tune difficulty to a target solve time of 1–4 seconds on representative client hardware.

Affected products

  • OpenReception appointment booking software prior to 1.0.6

Timeline

  • 2026-05-20: disclosed: GHSA-hm9g-mh7x-657g published on GitHub security advisory
  • 2026-08-06: advisory: CVE-2026-48082 published on NVD
  • 2026-08-06: patched: Version 1.0.6 released with increased difficulty from 4 to 5 hex zeros

References

Related threats