PT-2026-68735 · Unknown · Openreception
CVE-2026-48071
·
Published
2026-08-06
·
Updated
2026-08-08
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
OpenReception versions prior to 1.0.4
Description
The PIN-type challenge throttle uses
emailHash as the sole key within a central challenge throttle table shared across all tenants. This shared architecture allows an attacker who knows a patient's email to cause a denial of service for that patient across multiple tenants. By sending failed challenge responses to the /api/tenants/{id}/appointments/verify-challenge endpoint of one tenant, the attacker increments a shared row that is read by the /api/tenants/{id}/appointments/challenge endpoint of other tenants. This results in a lockout that escalates in duration from 60 seconds after 4 failed attempts, up to 60 minutes with repeated failures.Recommendations
Update to version 1.0.4.
Exploit
Fix
DoS
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openreception