PT-2026-95090 · Unknown · Openreception

·

CVE-2026-54460

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenReception versions prior to 1.1.1
Description An authentication bypass exists where the endpoint "POST /api/auth/passkeys" accepts a userId and a passkey without requiring an authenticated session. The system fails to call WebAuthnService.verifyRegistration() and does not bind enrollment to locals.user.id. An unauthenticated attacker with a public tenant ID and a target staff email can use the endpoint "GET /api/tenants/[id]/appointments/staff-public-keys" to find candidate userId values. By using UserService.addAdditionalPasskey() to store a controlled public key and attempting a login, an attacker can identify the correct userId and create a STAFF session. This allows unauthorized access to tenant data and the potential takeover of TENANT ADMIN accounts, which can lead to the modification or deletion of tenant resources and key shares, potentially making appointment data permanently undecryptable.
Recommendations Update to version 1.1.1.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54460
GHSA-G233-M625-M3PC

Affected Products

Openreception