CVE-2026-52841

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the provider. Any logged-in backend user (admin, provider, or secretary) rebinds a peer provider's Google sync to a Google account they control. The peer's appointments then sync into the attacker's calendar with each customer's name and email attached as attendee data. Version 1.6.0 patches the issue.
Configurations

No configuration.

History

14 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 16:17

Updated : 2026-07-14 16:42


NVD link : CVE-2026-52841

Mitre link : CVE-2026-52841

CVE.ORG link : CVE-2026-52841


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key