A vulnerability classified as critical was found in OpenReception appointment-booking-software up to 1.0.1. This affects an unknown function of the file /api/auth/register of the component Registration Handler. Such manipulation of the argument userId leads to reachable assertion.
This vulnerability is traded as CVE-2026-48087. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.