CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-52839

CVE-2026-52839: Cross-Provider Appointment Injection and Authorization Bypass in Easy!Appointments

Alon Barad
Alon Barad
Software Engineer

Jul 30, 2026·6 min read·94 visits

Executive Summary (TL;DR)

Authenticated providers can inject or reassign appointments into schedules of other providers due to missing session-boundary validation on mutation endpoints, compounded by a write-before-crash logic flaw.

An authorization bypass and logical 'write-before-crash' vulnerability in Easy!Appointments versions prior to 1.6.0 allows authenticated users with the 'Provider' role to inject unauthorized bookings into foreign providers' schedules or reassign existing appointments via parameter manipulation on the 'store' and 'update' endpoints.

Vulnerability Overview

Easy!Appointments is an open-source, self-hosted appointment scheduling application written in PHP on top of the CodeIgniter framework. The application uses a multi-tenant role model to separate system administrators, secretaries, providers, and customers. The 'Provider' role is designed to manage individual calendars, service availabilities, and customer appointments associated only with that specific provider account.

While the application successfully restricts read access boundaries—such as limiting the appointments returned in search results through the appointments/search endpoint—it does not enforce equivalent logical separations during data mutation operations. The endpoints responsible for persisting new appointments (appointments/store) and modifying existing ones (appointments/update) allow callers to supply arbitrary provider identifiers. This configuration exposes an insecure direct object reference (IDOR) vector to authenticated attackers.

Because the backend controller lacks verification checks to confirm that the submitted provider identifier corresponds to the active session user, authenticated providers can manipulate foreign calendars. An attacker with standard provider privileges can inject unauthorized appointments into another provider's schedule or hijack existing entries. This vulnerability breaks the primary multi-tenant isolation assumption of the platform.

Root Cause Analysis

The root cause of this vulnerability lies in the lack of session-based validation within the controller class located at application/controllers/Appointments.php. During HTTP POST requests to the store and update endpoints, the application decodes a JSON payload containing the appointment data structure. This structure includes the id_users_provider field, which determines the database association for the appointment.

The controller directly maps the request data to the database abstraction model without checking if the caller holds the appropriate permissions to write to the requested provider ID. The backend relies solely on the application-wide check that verifies whether the caller has the general privilege to create or edit appointments. It fails to apply contextual, row-level verification to ensure the caller's session matches the owner of the target schedule.

Furthermore, the store flow contains a logical 'write-before-crash' anomaly. After executing the database save operation, the code attempts to retrieve the newly written record using a find operation but incorrectly passes the complete associative appointment array instead of the integer insertion ID. This mismatch causes PHP to raise a fatal runtime TypeError, terminating execution. Because the database transaction is already committed before the crash occurs, the unauthorized injection succeeds despite the application returning an HTTP 500 error to the client.

Code Analysis

Analyzing the vulnerable code path in application/controllers/Appointments.php before version 1.6.0 reveals the unsafe parameter mapping. The JSON input is converted into an associative array, parsed for allowed database fields, and immediately processed by the active record model. The application processes the database write using trusted and untrusted inputs interchangeably.

// Vulnerable Controller Flow (Before 1.6.0)
public function store(): void
{
    // Missing validation to ensure session_id matches the submitted provider ID
    $appointment = json_decode(request('appointment'), true);
 
    $this->appointments_model->only($appointment, $this->allowed_appointment_fields);
    $this->appointments_model->optional($appointment, $this->optional_appointment_fields);
 
    // The application commits the arbitrary id_users_provider directly to the database
    $appointment_id = $this->appointments_model->save($appointment);
 
    // TYPE ERROR CRASH: The find() method expects an integer ID but receives the array
    $appointment = $this->appointments_model->find($appointment);
 
    $this->webhooks_client->trigger(WEBHOOK_APPOINTMENT_SAVE, $appointment);
}

The patched implementation in version 1.6.0 resolves this validation gap by actively checking the caller's session role. If the active session is associated with the 'Provider' role, the controller overwrites any client-provided id_users_provider key with the authenticated user ID stored in the server session. The update flow implements an identical mapping check to secure existing records.

// Patched Controller Flow (Version 1.6.0)
public function store(): void
{
    $appointment = json_decode(request('appointment'), true);
    if (!is_array($appointment)) {
        throw new InvalidArgumentException('Invalid appointment data provided.');
    }
 
    $user_id = (int) session('user_id');
    $role_slug = session('role_slug');
 
    // Strict session enforcement for the provider role
    if ($role_slug === DB_SLUG_PROVIDER) {
        $appointment['id_users_provider'] = $user_id;
    }
 
    $this->appointments_model->only($appointment, $this->allowed_appointment_fields);
    $this->appointments_model->optional($appointment, $this->optional_appointment_fields);
 
    $appointment_id = $this->appointments_model->save($appointment);
 
    // Fixed type argument prevents the runtime server crash
    $appointment = $this->appointments_model->find($appointment_id);
 
    $this->webhooks_client->trigger(WEBHOOK_APPOINTMENT_SAVE, $appointment);
}

Exploitation Mechanics

To exploit this vulnerability, an attacker must first obtain valid credentials associated with a 'Provider' account. Once authenticated, the attacker monitors network traffic to capture the structure of legitimate creation and modification requests sent to the backend endpoints. The target identifiers are gathered by viewing the public scheduling interface or querying public directories.

An attacker targets the appointments/store endpoint by formulating a POST request containing an appointment structure. By replacing the id_users_provider parameter with the ID of the target provider, the transaction is routed to the target provider's schedule. The attacker triggers the exploit payload directly over standard HTTP.

POST /appointments/store HTTP/1.1
Host: scheduling-system.local
Content-Type: application/x-www-form-urlencoded
Cookie: csrf_cookie_name=...; session_id=...
 
appointment=%7B%22id_users_provider%22%3A12%2C%22id_users_customer%22%3A45%2C%22id_services%22%3A2%2C%22start_datetime%22%3A%222026-08-01+10%3A00%3A00%22%2C%22end_datetime%22%3A%222026-08-01+11%3A00%3A00%22%7D

When the server processes this request, it writes the record to the database and returns an HTTP 500 response. This status code indicates a generic failure to the client but masks the successful injection of the record. The attacker can verify the injection by querying the target provider's public calendar page, which now registers the block.

Impact Assessment

The security impact of CVE-2026-52839 is rated as low-to-moderate with a CVSS v3.1 base score of 3.3. The vulnerability does not allow remote code execution or direct database exposure. However, it compromises data integrity and authorization boundaries within multi-tenant deployments of the application.

Because of this vulnerability, unauthorized users can modify, corrupt, or inject records into restricted schedules. In organizations with competing providers or sensitive internal workflows, this issue allows malicious actors to systematically block available slots or reassign high-value bookings. The silent success of the write operation complicates detection.

This behavior makes manual log inspections necessary because security systems might misinterpret the HTTP 500 error responses as simple system failures rather than successful exploitation attempts. The scope remains restricted to the database tables associated with Easy!Appointments scheduling records.

Remediation and Patches

The primary remediation for this vulnerability is to upgrade Easy!Appointments instances to version 1.6.0 or higher. Version 1.6.0 introduces input verification checks and enforces session-based provider parameters. This release also resolves the type error bug in the store endpoint, ensuring consistent error responses.

If upgrading is not immediately possible, security administrators can apply a manual code patch. This is done by modifying application/controllers/Appointments.php to include role checks that overwrite client-provided provider parameters with active session IDs. The type error bug must also be corrected to ensure correct webhook processing.

Organizations should also audit active database tables for historical inconsistencies. Queries can be executed to compare the logged creation user with the actual provider assigned to active bookings. This process helps locate historical indicators of compromise.

Official Patches

alextselegidisOfficial patch securing the appointments/store and appointments/update endpoints

Fix Analysis (1)

Technical Appendix

CVSS Score
3.3/ 10
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS Probability
0.15%
Top 96% most exploited

Affected Systems

Easy!Appointments

Affected Versions Detail

Product
Affected Versions
Fixed Version
Easy!Appointments
alextselegidis
< 1.6.01.6.0
AttributeDetail
CWE IDCWE-639
Attack VectorNetwork
CVSS v3.1 Score3.3 (Low)
Exploit StatusNone (No active public exploits)
CISA KEV StatusNot Listed
Affected Functionsappointments/store, appointments/update

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-639
Authorization Bypass Through User-Controlled Key

The system uses a user-controlled key to identify resources in an SQL transaction without verifying that the key belongs to the authenticated actor.

Vulnerability Timeline

Vulnerability patched in source code repository
2026-05-26
GitHub Security Advisory published and CVE-2026-52839 assigned
2026-07-14
NVD finalizes severity and analysis processing
2026-07-29

References & Sources

  • [1]GitHub Security Advisory GHSA-w8xc-8g92-v77h
  • [2]NVD CVE-2026-52839 Record
  • [3]Easy!Appointments Version 1.6.0 Release Tag

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•14 minutes ago•CVE-2026-107721
5.9

CVE-2026-107721: Time Validation Bypass in NearForm fast-jwt due to Loose Temporal Option Validation

NearForm fast-jwt prior to version 6.3.0 is vulnerable to an input validation flaw where configuring verifier properties (such as clockTolerance, clockTimestamp, and cacheTTL) with non-finite values like Infinity or NaN allows attackers to bypass temporal claim validations, including expiration (exp) and activation (nbf) boundaries. This validation bypass can result in unauthorized session persistence and cache poisoning.

Amit Schendel
Amit Schendel
1 views•6 min read
•about 1 hour ago•CVE-2026-107722
9.8

CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt

A critical cryptographic vulnerability in fast-jwt versions 6.2.x prior to 6.3.0 allows unauthenticated remote attackers to execute an asymmetric-to-symmetric algorithm confusion attack due to incomplete validation of leading non-whitespace prefixes.

Amit Schendel
Amit Schendel
2 views•5 min read
•about 2 hours ago•CVE-2026-107720
7.4

CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt

CVE-2026-107720 is a critical signature verification bypass vulnerability in NearForm's fast-jwt Node.js library. Under specific configurations where the token verifier is initialized with a falsy cryptographic key (such as an empty string or null) and a non-empty algorithms allowlist, the library erroneously skips signature validation. This allows unauthenticated remote attackers to submit fabricated, unsigned JSON Web Tokens and bypass the authorization boundary of the application entirely.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-107715
6.8

CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session Cookies) are dynamically re-applied to the subsequent request, bypassing the internal header-stripping logic. An attacker who controls a redirection endpoint can capture sensitive bearer tokens or cookies.

Alon Barad
Alon Barad
6 views•7 min read
•about 4 hours ago•CVE-2026-107399
6.8

CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize

An origin trust boundary failure in the Ruby mechanize library (prior to v2.14.1) allows unauthenticated remote web servers to harvest sensitive global request headers, such as Authorization Bearer tokens and cookies, by utilizing HTML-level meta-refresh redirection tags. Standard HTTP-level redirect boundaries were not applied to document-level redirects, creating a vector for cross-origin credential leakage during automated crawls.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 5 hours ago•CVE-2026-107718
6.1

CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server

CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.

Alon Barad
Alon Barad
6 views•6 min read