Junglewise Threat Intelligence

CVE-2026-52839: Easy!Appointments authorization bypass in appointment store and update

CVE-2026-52839 · Severity: low · CVSS 3.3 · Published 2026-07-14

Technologies: alextselegidis/easyappointments (Packagist), Alextselegidis Easy Appointments. Vendors: Packagist.

Executive brief

Easy!Appointments is an open-source appointment scheduling system. A security flaw allows an authenticated staff member (provider) to create or modify appointments for other staff members, which should normally be restricted. This could lead to scheduling disruptions, such as unauthorized double-bookings or staff members hiding their own appointments by moving them to a colleague's calendar.

Technical details

The vulnerability exists in the `appointments/store` and `appointments/update` endpoints of Easy!Appointments. While the application correctly filters search results by provider, these mutation endpoints only verify generic 'add' or 'edit' permissions and fail to validate that the `id_users_provider` field matches the authenticated user's session. An attacker with provider-level privileges can submit a crafted JSON payload to inject new appointments into another provider's schedule or reassign existing ones. Additionally, the `store` endpoint contains a 'write-before-crash' bug where the unauthorized record is committed to the database before a type error causes a 500 response, potentially masking the successful exploit. The issue is fixed in version 1.6.0.

Affected products

  • alextselegidis Easy!Appointments <= 1.5.2

Timeline

  • 2026-05-25: disclosed: Vulnerability reported by Yash Shendge
  • 2026-06-15: patched: Version 1.6.0 released
  • 2026-07-14: advisory: NVD publication date
  • 2026-07-29: advisory: GitHub Advisory published

References

Related threats