THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w8xc-8g92-v77h (low) — Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

[GHSA] GHSA-w8xc-8g92-v77h (low) — Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

medgithub_advisoriesPublished 2026-07-29

GHSA-w8xc-8g92-v77h Severity: low CVE: CVE-2026-52839

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

## Summary

Easy!Appointments correctly filters provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpo

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w8xc-8g92-v77h