Authorization Bypass in Easy!Appointments Booking::register
Easy!Appointments versions 1.6.0 and earlier are vulnerable to an authorization bypass allowing unauthenticated modification of appointments via the Booking::register function.
Easy!Appointments versions 1.6.0 and earlier contain an authorization bypass vulnerability within the Booking::register() function. This flaw permits unauthenticated attackers to manipulate appointment records by supplying an appointment ID without the required management hash. By enumerating sequential appointment IDs and setting a self-asserted 'manage_mode' flag, an attacker can modify appointment details, reassign appointments to attacker-controlled accounts, and extract management hashes for further actions like cancellation or rescheduling. This vulnerability poses a significant risk to organizations using the platform for scheduling, as it allows for unauthorized data access and the disruption of business operations through the manipulation of client information and schedules.
Impact
Successful exploitation allows unauthenticated actors to read and modify sensitive booking data across the platform. This could result in data exfiltration of customer information, service disruption through mass appointment cancellation, or unauthorized scheduling changes, directly impacting the availability and integrity of the service for legitimate users.
Recommendation
- Upgrade Easy!Appointments to a patched version beyond 1.6.0 immediately.
- Audit application access logs for recurring requests to the booking registration endpoint featuring sequentially incrementing ID parameters.
- Implement stricter server-side authorization checks for all appointment modification requests to ensure that 'manage_mode' flags are verified against server-stored session data rather than client-supplied input.
Immediate actions
Upgrade Easy!Appointments to a version beyond 1.6.0
Threat Hunt
Identify high-frequency, sequential requests to Booking::register or similar endpoints
Data: Web server access logs
Mitigations
Upgrade Easy!Appointments to version > 1.6.0
CVE-2026-108758