OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels (CVE-2026-48076) | HOL Guard CVE