CVE-2026-48086: OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Summary
OpenReception's appointment booking software had a critical flaw before version 1.0.2 where a TENANT_ADMIN (an administrator for one customer's account) could promote themselves to GLOBAL_ADMIN (full platform-wide control) through a single web request, because the system checked the format of the request but not whether the user was actually allowed to make that change. This allowed them to access and control all other customers' data on the platform, or in self-hosted versions, to create new accounts and modify system-wide settings they shouldn't access.
Solution / Mitigation
Update to version 1.0.2, which fixes the issue.
Vulnerability Details
9.9(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
network
low
low
none
August 6, 2026
Classification
Affected Vendors
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48086
First tracked: August 6, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 95%