What is CVE-2026-16624?
CVE-2026-16624 affects Cal.com OSS, involving a missing authorization check during webhook creation via teamId. Any authenticated user can inject an unvalidated teamId to create a webhook on any team, enabling the theft of booking data such as organizer/attendee emails, custom responses, and potentially video call passwords. Immediate patching with the vendor's security update is strongly recommended.
Azərbaycanca: CVE-2026-16624 Cal.com açıq mənbə platformasında aşkarlanıb və webhook yaradılması zamanı avtorizasiya çatışmazlığından qaynaqlanır. İstənilən autentifikasiya olunmuş istifadəçi teamId parametrini manipulyasiya edərək hər hansı komandaya aid webhook yarada, təşkilatçı/iştirakçı e-poçtları, fərdi cavablar və video-zəng parolları kimi həssas rezervasiya məlumatlarını ələ keçirə bilər. Dərhal Cal.com tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Who can exploit CVE-2026-16624?
Any authenticated user can exploit this vulnerability.
What data can be stolen through CVE-2026-16624?
It can lead to the theft of sensitive booking data such as organizer/attendee emails, custom responses, and potentially video call passwords.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.