Authorization Bypass in Easy!Appointments by Alex Tselegidis
CVE-2026-108758
8.8HIGH
What is CVE-2026-108758?
Easy!Appointments versions prior to 1.6.0 experience a vulnerability in the Booking::register() function that permits unauthorized attackers to alter appointments. By supplying an appointment ID devoid of its hash, attackers can exploit a self-asserted manage_mode flag to enumerate appointments sequentially. This enables them to overwrite appointment details, associate them with their own accounts, and acquire management hashes required for rescheduling or cancellation of appointments.
Affected Version(s)
easyappointments 0 <= 1.6.0
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
