CVE-2026-48087Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the `userId` in the URL belongs to that email. An unauthenticated attacker requests a challenge for their own email, generates a registration response with their own authenticator, and submits it against any victim user's URL. The challenge-vs-cookie email match passes, the WebAuthn ceremony validates, and `addPasskey` writes the attacker's credential into the victim's `user_passkey` rows. The next victim-email login accepts a passkey assertion from the attacker's authenticator and issues a session as the victim. User IDs are not strictly secret on this platform, but the exact set of exposure surfaces should be assessed by the maintainers. Staff-list endpoints return user IDs to authenticated tenant members per the route signature; live verification of all exposure surfaces (whether user IDs leak through any unauthenticated route, through invite-confirmation URLs, or through other administrative views) is part of the pending live PoC. Where the attacker knows the victim's email and userId, the analysis below becomes account takeover. Version 1.0.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-07: 2Mentions · 2026-08-10: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-10: 108-0708-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-072
Disclosure1General1
2026-08-101
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-48087 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST … https://www.cve.org/CVERecord?id=CVE-2026-48087

    Post summary

    The text merely notes that CVE‑2026‑48087 affected OpenReception before version 1.0.2, providing limited technical detail without information on exploitation, patches, or mitigation.

    000011.2K
    57.9K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-48087 Healthcare appointment SaaS WebAuthn passkey bypass could enable account takeover in public-facing healthcare appointment systems Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-06/TIER_2_CVE-2026-48087.md #CyberSecurity #HealthcareCybersecurity #VulnerabilityManagement

    Post summary

    The post announces a new WebAuthn passkey bypass vulnerability (CVE-2026-48087) affecting healthcare appointment SaaS, highlighting its potential for account takeover and providing a link to a detailed analysis.

    0000043
    59 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48087 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST … https://www.cve.org/CVERecord?id=CVE-2026-48087 ----- Traducción: CVE-2026-48087 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑48087 for OpenReception’s appointment software, highlighting the registration handler endpoint and linking to the CVE record, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000045
    98 followersView on X

Explore more