CVE-2026-55651 Details
Description
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue.
A vulnerability allowing excessive data exposure has been identified in Easy!Appointments version 1.5.2. This issue resides in the customers' search endpoint, where an authenticated user can access appointment hashes of other users. These hashes can be exploited to modify or delete appointments of different providers, leading to an appointment takeover. The vulnerability arises from a lack of proper authorization checks, allowing unauthorized access to appointment management features.
Users are advised to update to Easy!Appointments version 1.6.0, which addresses this vulnerability by implementing proper authorization checks in the customers' search endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-4vmm-5qvc-w5p7 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-4vmm-5qvc-w5p7 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Easy!Appointments | >= 1.5.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
Volerion