CVE-2026-16624
A critical flaw in Cal.com OSS lets any logged‑in user create a webhook for any team by supplying an arbitrary teamId. The webhook can then pull sensitive booking information, such as attendee emails and video‑call passwords.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Cal.com open‑source community edition, any installation that allows authenticated users to create webhooks.
Real-world impact
An attacker could harvest private booking details from any team, including email addresses, custom responses, and possibly video‑call passwords, by creating a malicious webhook.
Why this severity
The CVSS score of 9.6 reflects that the flaw is exploitable over the network, requires only low privilege, changes the scope of the affected component, and gives the attacker full confidentiality and integrity compromise of booking data.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 22, 2026 · 10d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.