PatchSiren cyber security CVE debrief
CVE-2026-48075 open-reception CVE debrief
CVE-2026-48075 is a MEDIUM-severity vulnerability in OpenReception's appointment booking software. The add-to-tunnel endpoint allows an unauthenticated attacker to create a new appointment row in any client tunnel. This vulnerability has significant implications for the security of client tunnels and appointment data. Users of OpenReception's appointment booking software, administrators of client tunnels, and security teams responsible for authentication and authorization should be aware of this issue and take necessary actions to mitigate it. The vulnerability was addressed in version 1.0.5.
- Vendor
- open-reception
- Product
- appointment-booking-software
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Users of OpenReception's appointment booking software, administrators of client tunnels, and security teams responsible for authentication and authorization should be aware of this vulnerability and take necessary actions to mitigate it. These stakeholders need to ensure that their systems are updated to version 1.0.5 or later to prevent exploitation. Additionally, they should review and restrict access to the add-to-tunnel endpoint, implement authentication and authorization for appointment creation, and monitor for any suspicious activity related to appointment bookings. It is essential for these stakeholders to understand the potential impact of this vulnerability on their systems and take proactive measures to protect their client tunnels and appointment data. This includes verifying the authenticity of appointment requests, restricting access to sensitive data, and implementing additional security controls to prevent similar vulnerabilities in the future. By taking these steps, stakeholders can help prevent potential attacks and maintain the security and integrity of their appointment booking systems. Furthermore, security teams should consider conducting regular security audits and penetration testing to identify and address any potential vulnerabilities before they can be exploited. By prioritizing the security of their appointment booking software, stakeholders can help protect their systems and data from potential threats. The CVE-2026-48075 vulnerability highlights the importance of robust authentication and authorization mechanisms in preventing unauthorized access to sensitive data. By learning from this vulnerability, stakeholders can improve their overall security posture and reduce the risk of similar vulnerabilities in the future. Therefore, it is crucial for stakeholders to take immediate action to address this vulnerability and ensure the security and integrity of their appointment booking systems. This requires a proactive and multi-faceted approach that includes updating software, restricting access, implementing security controls, and conducting regular security audits. By working together, stakeholders can help prevent potential attacks and
Technical summary
CVE-2026-48075 is a MEDIUM-severity vulnerability in OpenReception's appointment booking software. The add-to-tunnel endpoint allows an unauthenticated attacker to create a new appointment row in any client tunnel. The vulnerability was addressed in version 1.0.5. This issue arises from the lack of authentication and authorization checks in the add-to-tunnel endpoint, which enables an attacker to insert arbitrary appointment data into any client tunnel. The endpoint's validation mechanism only checks if a tunnel exists with the given emailHash, but it does not verify the caller's identity or their relationship to the supplied tunnelId. As a result, an attacker can create appointments with CONFIRMED status, controlled ciphertext fields, and arbitrary date and duration. This vulnerability can lead to unauthorized access and manipulation of appointment data, potentially affecting the integrity and confidentiality of client tunnel information.
Defensive priority
CVE-2026-48075 is a MEDIUM-severity vulnerability affecting OpenReception's appointment booking software. The vulnerability allows an unauthenticated attacker to create a new appointment row in any client tunnel. To address this vulnerability, users should update to version 1.0.5 or later.
Recommended defensive actions
- Update OpenReception's appointment booking software to version 1.0.5 or later
- Review and restrict access to the add-to-tunnel endpoint
- Implement authentication and authorization for appointment creation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE-2026-48075 vulnerability was reported in OpenReception's appointment booking software. The issue allows an attacker to create a new appointment row in any client tunnel without authentication. The vulnerability was addressed in version 1.0.5. Evidence is based on official CVE and NVD records.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:09.977Z and has not been modified since then.