Vulnerability Description
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/calcom/cal.diy/security/advisories/GHSA-4fwh-xxpv-xfm6
- https://vokecyber.com/research/calcom-cross-tenant-webhook-plant
- https://vokecyber.com/research/calcom-cross-tenant-webhook-plant
FAQ
What is CVE-2026-16624?
CVE-2026-16624 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including f...
How severe is CVE-2026-16624?
CVE-2026-16624 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-16624?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.