THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8hm4-r66f-29wr (low) — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

[GHSA] GHSA-8hm4-r66f-29wr (low) — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

medgithub_advisoriesPublished 2026-07-29

GHSA-8hm4-r66f-29wr Severity: low CVE: CVE-2026-52841

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

### Summary

`Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without che

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8hm4-r66f-29wr