CVE-2026-16624: CWE-639 Authorization Bypass Through User-Controlled Key in Cal.com Cal.diy
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
AI Analysis
Technical Summary
Cal.com Cal.diy contains an authorization bypass vulnerability (CWE-639) due to lack of validation on the teamId parameter during webhook creation. This allows authenticated users to create webhooks on teams they do not belong to, leading to unauthorized access to sensitive booking information. The vulnerability has a CVSS 3.1 base score of 9.6, indicating critical severity with network attack vector, low attack complexity, required privileges, no user interaction, and high impact on confidentiality and integrity.
Potential Impact
An attacker with valid authentication can bypass authorization controls to create webhooks on arbitrary teams, resulting in unauthorized disclosure of sensitive booking data such as organizer and attendee emails, custom responses, and potentially video-call passwords. This compromises user privacy and confidentiality of booking information. There is no indication of availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions where possible and monitor for suspicious webhook creation activity related to unauthorized teamIds.
CVE-2026-16624: CWE-639 Authorization Bypass Through User-Controlled Key in Cal.com Cal.diy
Description
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
CVSS v3.1
Score 9.6critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cal.com Cal.diy contains an authorization bypass vulnerability (CWE-639) due to lack of validation on the teamId parameter during webhook creation. This allows authenticated users to create webhooks on teams they do not belong to, leading to unauthorized access to sensitive booking information. The vulnerability has a CVSS 3.1 base score of 9.6, indicating critical severity with network attack vector, low attack complexity, required privileges, no user interaction, and high impact on confidentiality and integrity.
Potential Impact
An attacker with valid authentication can bypass authorization controls to create webhooks on arbitrary teams, resulting in unauthorized disclosure of sensitive booking data such as organizer and attendee emails, custom responses, and potentially video-call passwords. This compromises user privacy and confidentiality of booking information. There is no indication of availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions where possible and monitor for suspicious webhook creation activity related to unauthorized teamIds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-07-22T15:02:38.700Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a610e399c2644c7f87e16bd
Added to database: 07/22/2026, 18:38:49 UTC
Last enriched: 07/30/2026, 01:09:20 UTC
Last updated: 08/31/2026, 10:52:07 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.