Information disclosure in Easy!Appointments - CVE-2026-55651

 

Information disclosure in Easy!Appointments - CVE-2026-55651

Published: June 15, 2026


Vulnerability identifier: #VU134529
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55651
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify or delete other users' appointments.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the customers search endpoint when handling authenticated search requests. A remote user can obtain appointment hashes belonging to other users and reuse them to modify or delete other users' appointments.

The exposed hashes can also be used to view appointment information through appointment management functionality.


Affected software

Easy!Appointments

How to mitigate CVE-2026-55651

Install security update from vendor's website.

Easy!Appointments - update to 1.6.0

External References

Related Security Bulletins