CVE-2026-48075: OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the add-to-tunnel endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid tunnelId and any valid emailHash (the two need not belong to the same tunnel) results in an inserted appointment with status = "CONFIRMED", attacker-controlled ciphertext fields, attacker-controlled date and duration, and an attacker-chosen agent. The endpoint validates only that some tunnel exists with the given emailHash, then writes the appointment using the attacker-supplied tunnelId directly. The emailHash lookup is effectively an existence check on the tenant; it does not authenticate the caller as the owner of the supplied tunnelId. Combined with the absence of any session, Authorization header, booking access token, or PoW, this makes the endpoint accept arbitrary appointment writes into arbitrary tunnels. By contrast, the sibling endpoint create-new-client (used to bootstrap a brand-new client tunnel) requires a Bearer bootstrap booking access token issued by the bootstrap-challenge / bootstrap-verify flow. The add-to-tunnel endpoint, intended for return-clients booking additional appointments, has no equivalent gate. The application's own middleware confirms this is intentional: add-to-tunnel is explicitly listed in the apiAuthHandle public-route allowlist alongside the bootstrap and challenge endpoints (which legitimately have no session). Version 1.0.5 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenReception appointment booking software (add-to-tunnel endpoint fix)to a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48075?
CVE-2026-48075 has a medium severity rating of 6.5.
How do I fix CVE-2026-48075?
To mitigate CVE-2026-48075, upgrade OpenReception to version 1.0.5 or later.
What is the risk associated with CVE-2026-48075?
CVE-2026-48075 has a risk score of 45, indicating a significant potential for exploitation.
What are the implications of CVE-2026-48075?
CVE-2026-48075 allows unauthenticated users to inject arbitrary appointments into any client tunnel.
Who is affected by CVE-2026-48075?
Any users of OpenReception's appointment booking software prior to version 1.0.5 are affected by CVE-2026-48075.