Authorization Bypass in Easy!Appointments by Alex Tselegidis
CVE-2026-108758

8.8HIGH

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108758?

Easy!Appointments versions prior to 1.6.0 experience a vulnerability in the Booking::register() function that permits unauthorized attackers to alter appointments. By supplying an appointment ID devoid of its hash, attackers can exploit a self-asserted manage_mode flag to enumerate appointments sequentially. This enables them to overwrite appointment details, associate them with their own accounts, and acquire management hashes required for rescheduling or cancellation of appointments.

Affected Version(s)

easyappointments 0 <= 1.6.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.