PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48080 open-reception CVE debrief

CVE-2026-48080 debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:10.703Z and has not been modified since then. The NVD entry is currently Deferred. OpenReception's appointment booking software provides end-to-end encrypted appointment booking. Prior to version 1.0.2, a TENANT_ADMIN can access sensitive database credentials via the `GET /api/tenants/{id}` endpoint, potentially leading to data exposure and escalation. The vulnerability breaks per-tenant database isolation, allowing attackers to read or modify data across tenants.

Vendor
open-reception
Product
appointment-booking-software
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-09-08
Advisory published
2026-08-06
Advisory updated
2026-09-08

Who should care

Administrators and users of OpenReception's appointment booking software should assess exposure and prioritize remediation due to potential data exposure and escalation risks. This includes reviewing system configurations, monitoring for suspicious activity, and applying vendor guidance. Security teams should verify that compensating controls are in place for exposed systems and track exceptions during remediation.

Why it matters

CVE-2026-48080 requires immediate defensive priority due to potential data exposure and escalation risks in OpenReception's appointment booking software.

  • Potential data exposure and escalation risks for OpenReception users
  • TENANT_ADMIN access to sensitive database credentials
  • Possible lateral movement and exploitation of other tenant databases

Technical summary

CVE-2026-48080 is a vulnerability in OpenReception's appointment booking software that allows a TENANT_ADMIN to access sensitive database credentials via the `GET /api/tenants/{id}` endpoint. This access could lead to data exposure and escalation, breaking the per-tenant database isolation. The vulnerability is fixed in version 1.0.2. Operators should assess exposure and prioritize remediation due to potential risks. The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the scope of affected deployments.

Defensive priority

CVE-2026-48080 requires immediate defensive priority due to potential data exposure and escalation risks.

Recommended defensive actions

  • Review and update OpenReception appointment booking software to version 1.0.2 or later
  • Restrict access to the GET /api/tenants/{id} endpoint
  • Monitor for suspicious activity and potential data exposure
  • Implement compensating controls for exposed systems
  • Conduct an asset inventory to identify potentially affected systems
  • Track exceptions and retest remediated assets
  • Review relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in OpenReception's appointment booking software. The vulnerability allows a TENANT_ADMIN to access sensitive database credentials, potentially leading to data exposure and escalation. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessments. However, the scope of affected deployments and specific defensive measures require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48080 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48080

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48080 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48080

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/open-reception/appointment-booking-software/commit/ad9e49e3cf66b0cc9a327f6d8a895b23bbd6fea9

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-v7fw-6xpm-7gj9

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.