CVE-2026-16624: Cal.com Cal.diy

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.

Affected products

  • Cal.com Cal.diy: before 6.2.0 (fixed in 6.2.0)

Published 2026-07-22. Last modified 2026-07-27.