THREAT OPS › Threat News › [GHSA] GHSA-w8xc-8g92-v77h (low) — Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
[GHSA] GHSA-w8xc-8g92-v77h (low) — Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
GHSA-w8xc-8g92-v77h Severity: low CVE: CVE-2026-52839
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
## Summary
Easy!Appointments correctly filters provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpo
Indicators of compromise
- CVE-2026-52839cve
Original source: https://github.com/advisories/GHSA-w8xc-8g92-v77h