A vulnerability classified as critical was found in OpenReception appointment-booking-software up to 1.0.1. This affects an unknown function of the file /api/auth/register of the component Registration Handler. Such manipulation of the argument userId leads to reachable assertion.

This vulnerability is traded as CVE-2026-48087. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.