A critical privilege-escalation flaw tracked as CVE-2026-48086 affected OpenReception appointment-booking software before version 1.0.2, allowing a TENANT_ADMIN to promote themselves or another user in the same tenant to GLOBAL_ADMIN. The issue stemmed from the role-update handler accepting the GLOBAL_ADMIN enum in a single PUT request without enforcing a policy check, and after re-authentication the returned JWT reflected the elevated role. The vulnerability was rated CVSS 9.9 and classified as CWE-269 Improper Privilege Management.
Successful exploitation could grant cross-tenant administrative access in hosted deployments and broader unauthorized administrative control in self-hosted single-tenant environments. OpenReception addressed the issue in version 1.0.2, and the corresponding GitHub patch in src/routes/api/tenants/[id]/staff/[staffId]/+server.ts added an explicit authorization check that blocks assignment of the GLOBAL_ADMIN role by throwing an AuthorizationError during staff update operations.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for a critical OpenReception vulnerability was published, describing how a TENANT_ADMIN could promote themselves or a colleague to GLOBAL_ADMIN via a single PUT request in versions before 1.0.2. The advisory states the issue is remotely exploitable, affects hosted and self-hosted deployments, and was fixed in version 1.0.2.
A code change in OpenReception added an explicit authorization check in the tenant staff update endpoint to block assignment of the GLOBAL_ADMIN role, preventing privilege escalation through that route. The fix is associated with GitHub commit 8525d35 and corresponds to the remediation later described as version 1.0.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.