CVE-2026-48086: OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANTADMIN promotes themselves to platform-wide GLOBALADMIN through a single PUT request. The role-update handler accepts the GLOBALADMIN enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBALADMIN may grant GLOBALADMIN", so the schema validation IS the authorization decision. After re-login, the JWT contains the new role and the formerly-tenant-scoped admin reaches every other tenant on the platform. On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and tenant lifecycle. Plaintext appointment contents remain subject to the E2E model unless chained with the staff-crypto poisoning issue (V-4) or with staff-passkey hijacking (V-1). On a single-tenant self-hosted deployment it is still a privilege escalation because TENANTADMIN should not be able to create new tenants, modify global configuration, or manage other administrators. The same handler also accepts updates targeted at any colleague within the tenant. A tenant admin can promote a separate collaborator account instead of themselves, leaving their own audit trail clean while the platform-wide breach happens through a separate identity. Version 1.0.2 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenReceptionto a version that resolves this vulnerability.Fixed in 1.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48086?
The severity of CVE-2026-48086 is critical with a score of 9.9.
How do I fix CVE-2026-48086?
To fix CVE-2026-48086, upgrade to OpenReception version 1.0.2 or later.
What type of vulnerability is CVE-2026-48086?
CVE-2026-48086 is a vulnerability that allows a TENANT_ADMIN to self-promote to GLOBAL_ADMIN.
What are the potential impacts of CVE-2026-48086?
The potential impacts of CVE-2026-48086 include unauthorized administrative access and control over the entire platform.
Which systems are affected by CVE-2026-48086?
Systems using OpenReception's appointment booking software prior to version 1.0.2 are affected by CVE-2026-48086.