CVE-2026-16624
CVE-2026-16624
CVSS Score
9.6
EPSS Score
0.2%
EPSS Percentile
10th
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
| Vendor | cal.com |
| Product | cal.diy |
| Published | Jul 22, 2026 |
| Last Updated | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for cal.com cal.diy
Be the first to know when new critical vulnerabilities affecting cal.com cal.diy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Cal.com / Cal.diy
0 < 6.2.0