A vulnerability marked as critical has been reported in OpenReception Appointment Booking Software up to 1.0.1. Impacted is the function
SessionService.revokeSession of the file /logout of the component Logout Handler. The manipulation leads to improper authentication.
This vulnerability is documented as CVE-2026-48079. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.