THREAT OPS › Threat News › [NVD] CVE-2026-48078 (MEDIUM 5.3) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` fla
[NVD] CVE-2026-48078 (MEDIUM 5.3) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` fla
CVE-2026-48078 CVSS: 5.3 MEDIUM Published: 2026-08-06T22:17:10.420
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false` are intended t
Indicators of compromise
- CVE-2026-48078cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48078