Authorization bypass through user-controlled key in Easy!Appointments - CVE-2026-52837

 

Authorization bypass through user-controlled key in Easy!Appointments - CVE-2026-52837

Published: June 15, 2026


Vulnerability identifier: #VU134528
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52837
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in the booking reschedule view when handling a GET request to /index.php/booking/reschedule/{appointment_hash}. A remote attacker can send a request with a valid appointment hash to disclose sensitive information.

The response embeds the full customer record as inline JavaScript, exposing fields beyond those required by the reschedule interface.


Affected software

Easy!Appointments

How to mitigate CVE-2026-52837

Install security update from vendor's website.

Easy!Appointments - update to 1.6.0

External References

Related Security Bulletins