CVE-2026-48087: CWE-287: Improper Authentication in open-reception appointment-booking-software
CVE-2026-48087 is a critical improper authentication vulnerability in OpenReception's appointment booking software prior to version 1.0.2. The flaw allows an unauthenticated attacker to register a WebAuthn passkey credential under a victim's user ID by exploiting insufficient validation between the userId in the URL and the email associated with the registration cookie. This enables the attacker to impersonate the victim and gain unauthorized access to their account. The issue is fixed in version 1.0.2.
AI Analysis
Technical Summary
OpenReception's appointment booking software before version 1.0.2 contains an improper authentication vulnerability (CWE-287) in the registration handler at POST /api/auth/register/{userId}. The handler validates the WebAuthn challenge against the registration cookie's email but does not verify that the userId in the URL corresponds to that email. An attacker can request a challenge for their own email, generate a registration response with their own authenticator, and submit it against a victim's userId URL. Because the challenge and cookie email match, the WebAuthn ceremony succeeds, and the attacker's credential is written into the victim's user_passkey records. Consequently, the attacker can authenticate as the victim using their own passkey. User IDs are not strictly secret, and exposure surfaces should be assessed by maintainers. Version 1.0.2 addresses this vulnerability.
Potential Impact
Successful exploitation allows an unauthenticated attacker to perform account takeover by registering their own WebAuthn credential under a victim's user ID, thereby bypassing authentication controls. This leads to full compromise of the victim's account, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 9.8 (critical).
Mitigation Recommendations
Version 1.0.2 of OpenReception's appointment booking software fixes this vulnerability by properly validating that the userId in the registration URL matches the email associated with the registration cookie. Users and administrators should upgrade to version 1.0.2 or later to remediate this issue. No official patch link is provided; check the vendor's official channels for the update. Until patched, assess exposure of user IDs and restrict access to user ID information to reduce attack surface.
CVE-2026-48087: CWE-287: Improper Authentication in open-reception appointment-booking-software
Description
CVE-2026-48087 is a critical improper authentication vulnerability in OpenReception's appointment booking software prior to version 1.0.2. The flaw allows an unauthenticated attacker to register a WebAuthn passkey credential under a victim's user ID by exploiting insufficient validation between the userId in the URL and the email associated with the registration cookie. This enables the attacker to impersonate the victim and gain unauthorized access to their account. The issue is fixed in version 1.0.2.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/open-reception/appointment-booking-softwareRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenReception's appointment booking software before version 1.0.2 contains an improper authentication vulnerability (CWE-287) in the registration handler at POST /api/auth/register/{userId}. The handler validates the WebAuthn challenge against the registration cookie's email but does not verify that the userId in the URL corresponds to that email. An attacker can request a challenge for their own email, generate a registration response with their own authenticator, and submit it against a victim's userId URL. Because the challenge and cookie email match, the WebAuthn ceremony succeeds, and the attacker's credential is written into the victim's user_passkey records. Consequently, the attacker can authenticate as the victim using their own passkey. User IDs are not strictly secret, and exposure surfaces should be assessed by maintainers. Version 1.0.2 addresses this vulnerability.
Potential Impact
Successful exploitation allows an unauthenticated attacker to perform account takeover by registering their own WebAuthn credential under a victim's user ID, thereby bypassing authentication controls. This leads to full compromise of the victim's account, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 9.8 (critical).
Mitigation Recommendations
Version 1.0.2 of OpenReception's appointment booking software fixes this vulnerability by properly validating that the userId in the registration URL matches the email associated with the registration cookie. Users and administrators should upgrade to version 1.0.2 or later to remediate this issue. No official patch link is provided; check the vendor's official channels for the update. Until patched, assess exposure of user IDs and restrict access to user ID information to reduce attack surface.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:40:45.833Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a750706bf8831d5395f5a8e
Added to database: 08/06/2026, 22:13:26 UTC
Last enriched: 08/06/2026, 22:58:26 UTC
Last updated: 08/06/2026, 23:50:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.