THREAT OPS › Threat News › [GHSA] GHSA-8hm4-r66f-29wr (low) — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
[GHSA] GHSA-8hm4-r66f-29wr (low) — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
GHSA-8hm4-r66f-29wr Severity: low CVE: CVE-2026-52841
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
### Summary
`Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without che
Indicators of compromise
- CVE-2026-52841cve
- mallory@x.testemail
- carol@target.testemail
Original source: https://github.com/advisories/GHSA-8hm4-r66f-29wr