SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16624

CRITICAL · CVSS 9.6 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The vulnerability allows any authenticated user to exploit the lack of authorization in webhook teamId creation, enabling them to inject unvalidated teamIds and create webhooks for any team. This could lead to unauthorized access to sensitive booking data, including organizer and attendee emails, custom responses, and potentially video-call passwords. Organizations using Cal.com OSS should prioritize addressing this critical issue to protect user data and maintain the integrity of their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16624
Severity
CRITICAL
CVSS
9.6
EPSS
0.28%

Original NVD Description

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.