PT-2026-68736 · Unknown · Openreception
CVE-2026-48074
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenReception versions prior to 1.0.6
Description
An issue exists in the appointment booking platform where a TENANT ADMIN can inadvertently delete pending invites belonging to other tenants. When deleting a staff user, the
StaffService.deleteStaffMember() function performs an invite cleanup in the user invite table using only the email variable without a tenantId predicate. This allows an administrator in one tenant to remove pending invites for any user sharing the same email address across different tenants.Recommendations
Update to version 1.0.6.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openreception