A vulnerability described as critical has been identified in OpenReception appointment-booking-software up to 1.0.5. The affected element is an unknown function of the file /api/tenants/{id}/appointments/bootstrap-challenge of the component Bootstrap Challenge. The manipulation of the argument tunnelId/clientPublicKey/emailHash results in allocation of resources.

This vulnerability is reported as CVE-2026-48082. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.