CVE-2026-54460: OpenReception Unauthenticated Passkey Injection
ID: f65413e5-7191-5d71-a860-3d01d302e170
STIX ID: report--f65413e5-7191-5d71-a860-3d01d302e170
Feed Name: CosmicBytez Labs
OpenReception patched CVE-2026-54460, a critical (CVSS 9.8) unauthenticated passkey-registration vulnerability in POST /api/auth/passkeys that allowed remote attackers to bind attacker-controlled WebAuthn credentials to staff accounts and achieve full account takeover; the issue is fixed in OpenReception 1.1.1, and affected customers are advised to upgrade immediately, audit the userPasskey table, force re-registration of passkeys, and have staff review accounts for unrecognized credentials or sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
