Executive brief
OpenReception is an end-to-end encrypted appointment booking platform used by healthcare and other organizations to securely schedule appointments. Versions before 1.0.2 fail to rate-limit failed passphrase login attempts, allowing attackers to conduct unlimited brute-force attacks against known email addresses. An attacker can test 10 password guesses per second per account without triggering any throttle, making it practical to compromise accounts with weak or previously-leaked passwords in hours or days.
Technical details
The vulnerability is a missing rate-limiting control on the passphrase authentication endpoint (`/api/auth/login`). The application implements per-account throttling (returning HTTP 429 after ~19 attempts) on the WebAuthn challenge endpoint, but this same throttle logic was not applied to the passphrase branch, leaving it unprotected against credential stuffing and dictionary attacks. Failed attempts are not recorded in the throttle counter, allowing attackers to submit guesses at ~10 per second (limited only by Argon2 verification cost of ~100ms per attempt). Combined with a weak 12-character minimum passphrase policy without entropy checks, common patterns such as `Spring2026!XX` are realistically crackable on a single CPU in days or on a GPU farm in hours. The fix in version 1.0.2 adds throttling to the passphrase path, bringing it into parity with the WebAuthn protection.
Affected products
- OpenReception Appointment Booking < 1.0.2
Timeline
- 2026-05-20: disclosed: Advisory GHSA-hhg5-xmjg-3m93 published
- 2026-08-06: patched: Version 1.0.2 includes fix; CVE-2026-48084 published