CRITICAL
CVE-2026-16624
Published Jul 22, 2026
9.6
CRITICALCVSS 3.1
EPSS 0.40%
Description
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
Affected products
-
Affected
- ≥ 0, < 6.2.0
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jul 22, 2026
Updated Jul 27, 2026
Reserved Jul 22, 2026
Link CVE-2026-16624
CISA Vulnrichment
Updated Jul 27, 2026
Red Hat
No data
GitHub
No data