CVE-2026-54460: OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind enrollment to locals.user.id. An unauthenticated attacker who knows the public tenant ID and the target staff email can use the public booking bootstrap and GET /api/tenants/[id]/appointments/staff-public-keys to obtain candidate userId values. The attacker first causes UserService.addAdditionalPasskey to store a controlled public key for a candidate userId, then attempts login with the target email; the login check compares verificationResult.userId with the email-resolved account and reveals whether the injected credential belongs to that target. Repeating this injection-before-login sequence identifies the matching userId, and the normal login endpoint accepts the attacker's assertion for the stored key and creates a STAFF session. The session can expose tenant data and reveal TENANTADMIN identifiers for further takeover; GLOBALADMIN accounts are not reachable through this tenant-scoped path. A hijacked TENANTADMIN can modify or delete tenant resources and key shares, potentially making appointment data permanently undecryptable and taking booking services offline. This issue is fixed in version 1.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenReception appointment booking softwareto a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
Which releases are affected?
OpenReception versions prior to 1.1.1 are affected.
What information does an attacker need to target an account?
The attacker needs the public tenant ID and the target staff member’s email address. They can use public booking bootstrap functionality and the staff-public-keys endpoint to obtain candidate userId values.
Is prior authentication required to add the attacker-controlled credential?
No. The vulnerable passkey enrollment endpoint accepts a request-body userId and attacker-supplied passkey without an authenticated session, and it does not verify the WebAuthn registration or bind enrollment to the logged-in user.
What level of access can result from successful exploitation?
An attacker can create a STAFF session for the targeted account, exposing tenant data. That access may reveal TENANT_ADMIN identifiers that can be used for further takeover; GLOBAL_ADMIN accounts are not reachable through the described attack path.