Junglewise Threat Intelligence

CVE-2026-48087: OpenReception appointment booking WebAuthn passkey injection

CVE-2026-48087 · Severity: critical · CVSS 9.8 · Published 2026-08-06

Technologies: OpenReception Appointment-Booking-Software. Vendors: OpenReception.

Executive brief

OpenReception is an appointment booking platform that uses end-to-end encryption and WebAuthn passkey authentication. A critical flaw in the registration handler allows an unauthenticated attacker to inject their own passkey credential into any victim's account if the attacker knows the victim's email and user ID. An attacker can then log in as the victim and gain full account access, including administrative privileges and decryption capabilities.

Technical details

The vulnerability is a WebAuthn passkey injection flaw in the POST /api/auth/register/{userId} endpoint. The registration handler validates that the WebAuthn challenge matches the registration cookie's email, and validates the WebAuthn ceremony itself, but fails to verify that the userId in the URL belongs to the attacker's email. An unauthenticated attacker requests a challenge for their own email, generates a valid WebAuthn registration response using their own authenticator, and submits it against a victim's user ID. The challenge-versus-email validation passes, the WebAuthn ceremony succeeds, and the attacker's credential is written to the victim's user_passkey database rows. On subsequent login, the victim's email can be authenticated using the attacker's passkey, issuing a session token in the victim's name. Exploitation requires network access to the OpenReception instance and knowledge of both the victim's email and userId; user IDs may be discoverable through staff lists or other endpoints. Version 1.0.2 fixes the issue by validating that the target userId matches the email's owner.

Affected products

  • OpenReception appointment-booking-software < 1.0.2

Timeline

  • 2026-05-20: disclosed: GitHub Security Advisory GHSA-j9rw-x2wv-h5rj published
  • 2026-05-20: patched: Version 1.0.2 released with fix
  • 2026-08-06: advisory: CVE-2026-48087 published to NVD

References

Related threats