Vulnerability Description
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the provider. Any logged-in backend user (admin, provider, or secretary) rebinds a peer provider's Google sync to a Google account they control. The peer's appointments then sync into the attacker's calendar with each customer's name and email attached as attendee data. Version 1.6.0 patches the issue.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/alextselegidis/easyappointments/commit/4b2d245d2cd2058dc76e05
- https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-8hm4
- https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-8hm4
FAQ
What is CVE-2026-52841?
CVE-2026-52841 is a vulnerability with a CVSS score of 3.1 (LOW). Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, ...
How severe is CVE-2026-52841?
CVE-2026-52841 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-52841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.