Back to overview

CVE-2026-16624

CRITICAL Exploitation: PoC
9.6
CVSS 3.1
Description
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.

Metadata

CVE ID
CVE-2026-16624
State
PUBLISHED
Assigner
certcc
Reserved
2026-07-22 15:02 UTC
Published
2026-07-22 18:31 UTC
Last updated
2026-07-27 17:10 UTC
Primary CWE
CWE-639
CWE-639 Authorization Bypass Through User-Controlled Key
Vendor / Product
Cal.com / Cal.diy
Sources
cve.org  ·  NVD

Severity & Metrics

9.6 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cal.com Cal.diy — 0 < 6.2.0
Weakness (CWE)
CWESourceDescription
— cna CWE-639 Authorization Bypass Through User-Controlled Key
CWE-639 adp CWE-639 Authorization Bypass Through User-Controlled Key
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.6 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Back to overview