CVE-2026-55651

HIGH

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Title source: cna
STIX 2.1

Description

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0019
EPSS Percentile 8.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
alextselegidis/easyappointments Packagist
alextselegidis/easyappointments = 1.5.2
Published Jul 14, 2026
Tracked Since Jul 14, 2026