CVE-2026-108758
Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id without its hash. Attackers can enumerate sequential appointment ids with a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled customers, and obtain management hashes for rescheduling or cancellation.
| CWE | CWE-639 |
| Vendor | alextselegidis |
| Product | easyappointments |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for alextselegidis easyappointments
Be the first to know when new high vulnerabilities affecting alextselegidis easyappointments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Affected Versions
alextselegidis / easyappointments
0 โค 1.6.0
References
hackmd.io: https://hackmd.io/@haind/easyappointments-booking-register-appointment-takeover github.com: https://github.com/alextselegidis/easyappointments/blob/4bc7ecd51f3dade8e041558f2c23dda65bd6c43e/application/controllers/Booking.php#L368-L587 github.com: https://github.com/alextselegidis/easyappointments/commit/09c6fb30b6aac0830a820d6bec3d2eb241daf150 github.com: https://github.com/alextselegidis/easyappointments vulncheck.com: https://www.vulncheck.com/advisories/easy-appointments-through-1.6.0-authorization-bypass-via-booking-register-endpoint
Credits
HaiND from the Post and Telecommunication Institute of Technology