Bookly <=28.1 - IDOR Unauthenticated Sensitive Data Access CVE-2026-89063

Detectable with
Network Scanner
Scan engine
Nuclei
Cisa Kev
No
Exploitable with Sniper
No
CVE Published
Sep 16, 2026
Detection added at
Software Type
Not available
Vendor
bookly
Product
bookly-responsive-appointment-booking-tool

Detect this vulnerability now!

Check your clients' targets (or your own) for this vulnerability and thousands more! Get proof for validation with our ethical hacking toolkit.