PT-2026-68735 · Unknown · Openreception

CVE-2026-48071

·

Published

2026-08-06

·

Updated

2026-08-08

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenReception versions prior to 1.0.4
Description The PIN-type challenge throttle uses emailHash as the sole key within a central challenge throttle table shared across all tenants. This shared architecture allows an attacker who knows a patient's email to cause a denial of service for that patient across multiple tenants. By sending failed challenge responses to the /api/tenants/{id}/appointments/verify-challenge endpoint of one tenant, the attacker increments a shared row that is read by the /api/tenants/{id}/appointments/challenge endpoint of other tenants. This results in a lockout that escalates in duration from 60 seconds after 4 failed attempts, up to 60 minutes with repeated failures.
Recommendations Update to version 1.0.4.

Exploit

Fix

DoS

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48071
GHSA-F778-WF9X-3QF9

Affected Products

Openreception