CVE-2026-52841: CWE-639: Authorization Bypass Through User-Controlled Key in alextselegidis easyappointments
Easy!Appointments versions prior to 1.6.0 contain an authorization bypass vulnerability in the Google OAuth integration. The application stores a URL-supplied provider_id in the session without verifying ownership, allowing any logged-in backend user to rebind another provider's Google sync to their own account. This results in unauthorized access to peer providers' appointment data, including customer names and emails. Version 1.6.0 addresses this issue.
AI Analysis
Technical Summary
In Easy!Appointments before version 1.6.0, the Google OAuth implementation at application/controllers/Google.php improperly trusts a URL-supplied provider_id parameter and stores it in the session. The oauth_callback function then saves the issued Google OAuth token against this provider_id without verifying that the caller owns the provider. Consequently, any authenticated backend user (admin, provider, or secretary) can rebind another provider's Google calendar sync to their own Google account. This leads to unauthorized synchronization of the peer provider's appointments, exposing customer attendee data such as names and emails. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Potential Impact
An attacker with any backend login privileges can hijack another provider's Google calendar synchronization, gaining unauthorized access to appointment details including customer names and email addresses. The confidentiality of customer data is compromised, but the vulnerability does not affect availability or integrity beyond this scope. The CVSS score is 3.1 (low severity), reflecting the requirement for authenticated access and high attack complexity.
Mitigation Recommendations
Upgrade Easy!Appointments to version 1.6.0 or later, where this authorization bypass vulnerability has been fixed. There is no official patch advisory provided, but the vendor has released version 1.6.0 to address the issue. Until upgrading, restrict backend user privileges to trusted personnel only to reduce risk.
CVE-2026-52841: CWE-639: Authorization Bypass Through User-Controlled Key in alextselegidis easyappointments
Description
Easy!Appointments versions prior to 1.6.0 contain an authorization bypass vulnerability in the Google OAuth integration. The application stores a URL-supplied provider_id in the session without verifying ownership, allowing any logged-in backend user to rebind another provider's Google sync to their own account. This results in unauthorized access to peer providers' appointment data, including customer names and emails. Version 1.6.0 addresses this issue.
CVSS v3.1
Score 3.1low
Affected software
pkg:github/alextselegidis/easyappointmentsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Easy!Appointments before version 1.6.0, the Google OAuth implementation at application/controllers/Google.php improperly trusts a URL-supplied provider_id parameter and stores it in the session. The oauth_callback function then saves the issued Google OAuth token against this provider_id without verifying that the caller owns the provider. Consequently, any authenticated backend user (admin, provider, or secretary) can rebind another provider's Google calendar sync to their own Google account. This leads to unauthorized synchronization of the peer provider's appointments, exposing customer attendee data such as names and emails. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Potential Impact
An attacker with any backend login privileges can hijack another provider's Google calendar synchronization, gaining unauthorized access to appointment details including customer names and email addresses. The confidentiality of customer data is compromised, but the vulnerability does not affect availability or integrity beyond this scope. The CVSS score is 3.1 (low severity), reflecting the requirement for authenticated access and high attack complexity.
Mitigation Recommendations
Upgrade Easy!Appointments to version 1.6.0 or later, where this authorization bypass vulnerability has been fixed. There is no official patch advisory provided, but the vendor has released version 1.6.0 to address the issue. Until upgrading, restrict backend user privileges to trusted personnel only to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-08T18:41:27.724Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a565a3b68715ace43c7b641
Added to database: 07/14/2026, 15:48:11 UTC
Last enriched: 07/30/2026, 07:20:23 UTC
Last updated: 08/26/2026, 10:52:09 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.