External risk intelligence

OpenReception Appointment Booking Software Credential Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-54460

The software is designed as a public-facing appointment booking platform. The vulnerable endpoints, including the public booking bootstrap and authentication APIs, are intended to be internet-accessible to allow external users to book appointments and staff to manage them.

Missing Authentication

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE concerns a vulnerability in OpenReception's appointment booking software that could allow an unauthenticated attacker to gain unauthorized access to tenant administrative privileges. This could lead to the modification or deletion of tenant resources, potentially causing data loss and service disruption. The main concern is confirming relevance and exposure to this specific software.

  • Allows attackers to impersonate staff.
  • Compromise appointment data and services.
  • Confirm software use and assess risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by first discovering a target staff member's user ID through public booking interactions. The attacker then uses this ID to add a malicious passkey, effectively hijacking the staff account during a subsequent login attempt. This allows them to gain tenant-level administrative access, with the potential to disrupt booking services.

  • Requires public tenant ID and staff email.
  • Login endpoint accepts attacker's assertion.
  • Risk of tenant data exposure and service disruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain unauthorized access to tenant data and potentially disrupt booking services. By manipulating the authentication process, an attacker could impersonate a tenant administrator, exposing sensitive tenant information and enabling further malicious actions within the tenant's scope. Global administrator accounts are not directly reachable through this attack path.

  • Tenant data and administrator identifiers at risk.
  • Attacker obtains user IDs and injects credentials.
  • Services could be taken offline or data made undecryptable.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Platform or Application Owner team is likely responsible for addressing this vulnerability within the OpenReception appointment booking software. The first practical step is to confirm the presence and exposure of this software across the environment, identify the specific instances and their business criticality, and then determine the accountable owner for remediation planning.

  • Confirm software presence and exposure.
  • Identify accountable owners for instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenReception appointment booking software?

OpenReception is a platform designed to manage and secure appointment scheduling through end-to-end encryption. It provides specialized interfaces for both public users to book services and staff members to manage their calendars and administrative tasks. Because it serves as a gateway for scheduling data, the software handles sensitive account information and authentication workflows to ensure only authorized staff can manage tenant resources.

What does CWE-306 mean for CVE-2026-54460?

CWE-306 refers to Missing Authentication for Critical Function. In this CVE, the software fails to properly check if a user is authenticated before allowing them to perform sensitive actions, such as registering a new passkey. Because the system skips necessary verification steps, an attacker can bypass standard login security and link their own unauthorized credentials to an existing staff account.

How does an attacker trigger this vulnerability?

An attacker triggers this by first identifying a target's user ID through public-facing API endpoints that list staff information. Once the ID is obtained, the attacker sends a request to the authentication API to inject a malicious passkey into the target's profile. This process does not require a prior session or valid password; however, it cannot be used to compromise global administrative accounts, as the scope of the vulnerability is limited to individual tenants.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this software is highly likely to be internet-accessible because it is specifically built for public appointment booking. Since the vulnerable authentication APIs are intended to be reachable to facilitate these public interactions, any instance exposed to the internet should be considered at risk, as the attack path relies on accessing these public-facing endpoints.

What steps should I take if I use this software?

The immediate priority is to locate all deployments of OpenReception within your environment and confirm their current version. Since this issue is resolved in version 1.1.1, you should coordinate with your application owners to schedule and apply the update. After patching, review your tenant logs for any unauthorized passkey registrations that may have occurred prior to the update.

References