Sceawere
Vulnerability Detail
CVE-2026-108758UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Easy!Appointments Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 4h ago
- Vendor
- alextselegidis
- Product
- easyappointments
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id without its hash. Attackers can enumerate sequential appointment ids with a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled customers, and obtain management hashes for rescheduling or cancellation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-11T13:17:21.020Z",
"pubdate": "2026-10-11T13:17:21.020Z",
"executiveSummary": "Easy!Appointments versions through 1.6.0 contain an authorization bypass vulnerability within the Booking::register() function. This flaw permits unauthenticated remote attackers to perform unauthorized modifications to existing appointment records. By exploiting improper access controls, an attacker can manipulate appointment data, reassociate bookings with arbitrary customer accounts, and retrieve sensitive management hashes. The vulnerability arises from the application's failure to adequately validate the relationship between a request and the security hash required for modification. Successful exploitation enables unauthorized rescheduling, cancellation, or data exfiltration of appointments, posing a significant risk to data integrity and system confidentiality. No authentication is required to initiate the attack, allowing any remote user to enumerate appointment identifiers sequentially to target arbitrary records. The impact involves potential compromise of scheduling systems, unauthorized access to user personal data, and service disruption.",
"technicalDetails": "The vulnerability resides in the Booking::register() function, which fails to enforce strict authorization checks when processing appointment modification requests. In a secure implementation, an appointment update requires the provision of a specific, cryptographically secure hash associated with the record to verify ownership or authorization. However, in versions through 1.6.0, the application logic allows for an authorization bypass if the request parameters are crafted effectively.\nThe attack flow begins with the attacker identifying the target appointment identifier, which is often sequential, allowing for straightforward enumeration. Upon initiating a request to the Booking::register() function, the attacker injects a self-asserted 'manage_mode' flag within the request payload. Because the application logic does not sufficiently validate the necessity of the hash parameter against the current session or authorization context when 'manage_mode' is toggled, the backend proceeds to process the input.\nBy manipulating the request parameters, the attacker can overwrite existing appointment details, such as service types, scheduled times, or customer associations. Specifically, the attacker can rebind the appointment to an attacker-controlled customer profile, effectively hijacking the booking record. Furthermore, successful manipulation returns the management hash associated with the appointment record. With this hash, the attacker gains full control over the appointment for future actions, including rescheduling or permanent cancellation, bypassing the intended security constraints of the application.\nThe root cause is a broken object-level authorization (BOLA) pattern where the function trusts user-supplied input regarding the management mode without verifying the request's authenticity or authorization level. The vulnerability is accessible over the network without requiring any prior authentication, placing the entire appointment database at risk of mass manipulation. The exploitation does not require advanced access, making it trivial for an unauthenticated remote actor to automate the enumeration and subsequent compromise of all appointments stored within the system."
}