CVE-2026-108758
Received Received - Intake

Authorization Bypass in Easy!Appointments via Booking::register()

Vulnerability report for CVE-2026-108758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id without its hash. Attackers can enumerate sequential appointment ids with a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled customers, and obtain management hashes for rescheduling or cancellation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
alextselegidis easyappointments 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Easy!Appointments through version 1.6.0. It allows unauthenticated attackers to modify any appointment by providing an appointment ID without its hash. Attackers can enumerate sequential IDs and use a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled accounts, and obtain management hashes for rescheduling or cancellation.

Detection Guidance

To detect this vulnerability, monitor for unauthorized POST requests to /index.php/booking/register with sequential appointment IDs and a manage_mode flag. Check server logs for repeated requests modifying appointment details without authentication. Test by attempting to modify an appointment with a guessed ID to see if changes succeed without proper validation.

Impact Analysis

Attackers can hijack appointments, steal sensitive data, manipulate schedules, and cancel or reschedule appointments without authorization. They can also overwrite customer PII like names, phone numbers, and addresses by submitting a victim's email address. The default configuration with booking enabled and CAPTCHA disabled exposes these attack paths.

Compliance Impact

This vulnerability could lead to violations of GDPR and HIPAA due to unauthorized access to and modification of personal data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. Unauthorized access or alteration of such data may result in non-compliance, legal penalties, and reputational damage.

Mitigation Strategies

Apply the patch from commit 09c6fb3 to enforce hash validation for rescheduling and remove ID parameters for new bookings. Disable the booking/register endpoint if not in use. Enable CAPTCHA and enforce strict CSRF checks. Monitor for suspicious activity and revoke any compromised appointment hashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart