Junglewise Threat Intelligence

CVE-2026-52841: Easy!Appointments authorization bypass in Google OAuth provider binding

CVE-2026-52841 · Severity: low · CVSS 3.1 · Published 2026-07-14

Technologies: alextselegidis/easyappointments (Packagist), Alextselegidis Easy Appointments. Vendors: Packagist.

Executive brief

Easy!Appointments is an open-source appointment scheduling application. A security flaw allows any staff member (such as a secretary or provider) to hijack the Google Calendar synchronization of other staff members. By doing so, an attacker can view private customer details like names and emails, delete existing appointments, or block out time on a colleague's schedule, potentially disrupting business operations and compromising client privacy.

Technical details

An authorization bypass exists in the `Google::oauth` and `oauth_callback` methods within `application/controllers/Google.php`. The `oauth` method accepts a user-supplied `provider_id` and stores it in the session without verifying if the authenticated user has permission to modify that specific provider's settings. During the subsequent OAuth callback, the application saves the resulting Google OAuth token to the `provider_id` stored in the session. An attacker with backend access (admin, provider, or secretary) can exploit this to bind their own Google account to a peer's profile. This allows the attacker to receive sync updates containing customer PII (name/email) and manipulate the victim's calendar via the synchronization loop. As of the advisory, no patch is specified, but the reporter suggests implementing the same permission checks used in other sync-management functions.

Affected products

  • alextselegidis Easy!Appointments <= 1.5.2

Timeline

  • 2026-06-15: disclosed
  • 2026-07-29: advisory

References

Related threats