Executive brief
OpenReception is an end-to-end encrypted appointment booking platform used by organizations to manage customer scheduling. Prior to version 1.0.1, the platform fails to properly authenticate requests to its admin account setup endpoint, allowing unauthenticated attackers to create new administrator accounts and gain complete control of the entire system. An attacker can enumerate users and access sensitive booking data with no prior credentials.
Technical details
The vulnerability is an authentication bypass in the `/setup/create-admin-account` endpoint (CWE-306: Missing Authentication Check). The root cause is insufficient authorization validation: the endpoint's GET-method guard only redirects requests but does not prevent POST submissions, and the form handler fails to recheck the `adminExists()` condition before creating a GLOBAL_ADMIN account. Any unauthenticated network attacker supplying a matching `Origin` header can POST to this endpoint after the instance is claimed and configured; the newly created account is immediately active with `is_active=true` and `confirmation_state=ACCESS_GRANTED`, bypassing email confirmation. No rate limiting exists, enabling rapid creation of multiple admin accounts. SvelteKit's same-origin CSRF protection is ineffective because curl, Burp, and server-side proxies can trivially supply the required header. The attacker gains full platform-level administrative control, access to all tenant data, and the ability to enumerate both users and bookings.
Affected products
- OpenReception OpenReception prior to 1.0.1
Timeline
- 2026-08-06: disclosed
- 2026: patched: version 1.0.1 available