CVE-2026-52839: CWE-639: Authorization Bypass Through User-Controlled Key in alextselegidis easyappointments
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update` only check generic appointment privileges and never verify that the submitted `id_users_provider` belongs to the current session. A normal authenticated provider can inject new appointments into another provider's schedule via `store`, or reassign existing appointments into a foreign provider's calendar via `update`. The `store` path contains an additional write-before-crash bug: the unauthorized row is committed to the database before the controller crashes on a type error, so the attacker receives an error response while the foreign appointment is already persisted. Version 1.6.0 patches the issue.
AI Analysis
Technical Summary
Easy!Appointments is a self-hosted appointment scheduler. In versions before 1.6.0, the application correctly filters provider-scoped appointments in search responses, indicating provider isolation as a security boundary. However, the direct mutation endpoints 'appointments/store' and 'appointments/update' only check generic appointment privileges without verifying that the 'id_users_provider' in the request belongs to the authenticated session. This allows an authenticated provider to inject new appointments into another provider's schedule or reassign existing appointments to a foreign provider's calendar. The 'store' endpoint also contains a bug where unauthorized database writes occur before a type error causes the controller to crash, resulting in the unauthorized appointment being persisted despite an error response. The issue is fixed in version 1.6.0.
Potential Impact
An authenticated provider can bypass intended authorization controls to create or modify appointments in other providers' schedules. This leads to unauthorized data manipulation and potential disruption of appointment management. The vulnerability does not affect confidentiality or availability but impacts data integrity and authorization boundaries.
Mitigation Recommendations
Upgrade to Easy!Appointments version 1.6.0 or later, where this authorization bypass vulnerability is fixed. No other mitigations are indicated in the vendor advisory. Patch status is not explicitly confirmed in the advisory, but version 1.6.0 is stated as the fixed version.
CVE-2026-52839: CWE-639: Authorization Bypass Through User-Controlled Key in alextselegidis easyappointments
Description
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update` only check generic appointment privileges and never verify that the submitted `id_users_provider` belongs to the current session. A normal authenticated provider can inject new appointments into another provider's schedule via `store`, or reassign existing appointments into a foreign provider's calendar via `update`. The `store` path contains an additional write-before-crash bug: the unauthorized row is committed to the database before the controller crashes on a type error, so the attacker receives an error response while the foreign appointment is already persisted. Version 1.6.0 patches the issue.
CVSS v3.1
Score 3.3low
Affected software
pkg:github/alextselegidis/easyappointmentsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Easy!Appointments is a self-hosted appointment scheduler. In versions before 1.6.0, the application correctly filters provider-scoped appointments in search responses, indicating provider isolation as a security boundary. However, the direct mutation endpoints 'appointments/store' and 'appointments/update' only check generic appointment privileges without verifying that the 'id_users_provider' in the request belongs to the authenticated session. This allows an authenticated provider to inject new appointments into another provider's schedule or reassign existing appointments to a foreign provider's calendar. The 'store' endpoint also contains a bug where unauthorized database writes occur before a type error causes the controller to crash, resulting in the unauthorized appointment being persisted despite an error response. The issue is fixed in version 1.6.0.
Potential Impact
An authenticated provider can bypass intended authorization controls to create or modify appointments in other providers' schedules. This leads to unauthorized data manipulation and potential disruption of appointment management. The vulnerability does not affect confidentiality or availability but impacts data integrity and authorization boundaries.
Mitigation Recommendations
Upgrade to Easy!Appointments version 1.6.0 or later, where this authorization bypass vulnerability is fixed. No other mitigations are indicated in the vendor advisory. Patch status is not explicitly confirmed in the advisory, but version 1.6.0 is stated as the fixed version.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-08T18:41:27.724Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a565a3b68715ace43c7b624
Added to database: 07/14/2026, 15:48:11 UTC
Last enriched: 07/29/2026, 21:20:40 UTC
Last updated: 08/22/2026, 22:52:14 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.