CVE-2026-48088 | open-reception appointment-booking-software up to 1.0.3 Registration Flow crypto email authorization
A vulnerability labeled as critical has been found in open-reception appointment-booking-software up to 1.0.3. This issue affects some unknown processing of the file /api/tenants/{tenantId}/staff/{staffId}/crypto of the component Registration Flow. Executing a manipulation of the argument email can lead to authorization bypass.
This vulnerability is registered as CVE-2026-48088. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.