๐Ÿ” CVE Alert

CVE-2026-16624

UNKNOWN 0.0

CVE-2026-16624

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.

Vendor cal.com
Product cal.diy
Published Jul 22, 2026
Last Updated Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for cal.com cal.diy

Be the first to know when new unknown vulnerabilities affecting cal.com cal.diy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Cal.com / Cal.diy
0 < 6.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/calcom/cal.diy/security/advisories/GHSA-4fwh-xxpv-xfm6 vokecyber.com: https://vokecyber.com/research/calcom-cross-tenant-webhook-plant