calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
Published Oct 2, 2026
5.3
MEDIUMCVSS 4.0
Description
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Affected products
-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version 6.2.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C
1 other source (NVD) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C
AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C
1 other source (NVD) ▾
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (7)
- https://github.com/calcom/cal.diy/ product
- https://github.com/calcom/cal.diy/issues/29802 exploitissue-tracking
- https://github.com/calcom/cal.diy/pull/30253 issue-trackingpatch
- https://vuldb.com/cve/CVE-2026-104054 third-party-advisory
- https://vuldb.com/submit/959492 third-party-advisory
- https://vuldb.com/vuln/412762 vdb-entrytechnical-description
- https://vuldb.com/vuln/412762/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/calcom/cal.diy/ | product | |
| https://github.com/calcom/cal.diy/issues/29802 | exploitissue-tracking | |
| https://github.com/calcom/cal.diy/pull/30253 | issue-trackingpatch | |
| https://vuldb.com/cve/CVE-2026-104054 | third-party-advisory | |
| https://vuldb.com/submit/959492 | third-party-advisory | |
| https://vuldb.com/vuln/412762 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/412762/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.