Back

CRITICAL

CVE-2026-16624

Published Jul 22, 2026

Description

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner certcc
Published Jul 22, 2026
Updated Jul 27, 2026
Reserved Jul 22, 2026

CISA Vulnrichment

Updated Jul 27, 2026

NVD

Status Awaiting Analysis
Modified Jul 27, 2026

Red Hat

No data

ENISA EUVD

Assigner certcc
Published Jul 22, 2026
Updated Jul 27, 2026

GitHub

No data