CVE-2026-48083: OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits

Published Aug 6, 2026
·
Updated

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the /api/log endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout log, interprets newline characters as real line breaks, and enforces no size or rate limits. Three independent abuse modes follow: log injection (forge log lines that look like legitimate system events), log volume DoS (saturate the logging pipeline at sustained 100+ requests per second of small messages), and oversized-payload submission (100 KB payloads accepted; larger sizes not tested). The most operationally damaging mode is log injection. An attacker can inject lines that an operator scanning logs would mistake for real system errors, mask their own activity behind fake noise, or pollute SIEM alerting rules with crafted false positives. A line such as [error]: injected admin error injected from an unauthenticated source is indistinguishable from the application's own error output once written to disk. Version 1.0.2 fixes the issue.

Affected Software

1 affected component
OpenReception appointment booking software<1.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenReception appointment booking software (/api/log CRLF/log injection) to a version that resolves this vulnerability.

    Fixed in 1.0.2

Event History

Aug 6, 2026
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48083?

The severity of CVE-2026-48083 is medium with a score of 6.5.

2

How do I fix CVE-2026-48083?

To fix CVE-2026-48083, update OpenReception to version 1.0.2 or later.

3

What type of attack does CVE-2026-48083 allow?

CVE-2026-48083 allows for CRLF injection attacks through unauthenticated POST requests.

4

What are the potential impacts of CVE-2026-48083?

CVE-2026-48083 can lead to arbitrary content being written into the application logs, potentially allowing for further exploitation.

5

Is authentication required to exploit CVE-2026-48083?

No, authentication is not required to exploit CVE-2026-48083, making it particularly concerning.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203