CVE-2026-16624
CVE-2026-16624
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
| Vendor | cal.com |
| Product | cal.diy |
| Published | Jul 22, 2026 |
| Last Updated | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for cal.com cal.diy
Be the first to know when new unknown vulnerabilities affecting cal.com cal.diy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Cal.com / Cal.diy
0 < 6.2.0