PT-2026-95090 · Unknown · Openreception
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenReception versions prior to 1.1.1
Description
An authentication bypass exists where the endpoint "POST /api/auth/passkeys" accepts a
userId and a passkey without requiring an authenticated session. The system fails to call WebAuthnService.verifyRegistration() and does not bind enrollment to locals.user.id. An unauthenticated attacker with a public tenant ID and a target staff email can use the endpoint "GET /api/tenants/[id]/appointments/staff-public-keys" to find candidate userId values. By using UserService.addAdditionalPasskey() to store a controlled public key and attempting a login, an attacker can identify the correct userId and create a STAFF session. This allows unauthorized access to tenant data and the potential takeover of TENANT ADMIN accounts, which can lead to the modification or deletion of tenant resources and key shares, potentially making appointment data permanently undecryptable.Recommendations
Update to version 1.1.1.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openreception