Back to overview

CVE-2025-66489

CRITICAL
9.9
CVSS 4.0
Description
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.

Metadata

CVE ID
CVE-2025-66489
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-12-02 22:44 UTC
Published
2025-12-03 19:44 UTC
Last updated
2025-12-03 21:48 UTC
Primary CWE
CWE-303
CWE-303: Incorrect Implementation of Authentication Algorith…
Vendor / Product
calcom / cal.com
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
calcom cal.com < 5.9.8
Weakness (CWE)
CWESourceDescription
CWE-303 cna CWE-303: Incorrect Implementation of Authentication Algorithm
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N
References (1)
Back to overview