CVE-2026-16624 - CVE-2026-16624
CVE ID :CVE-2026-16624
Published : July 22, 2026, 6:31 p.m. | 19 minutes ago
Description :Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 22, 2026, 6:31 p.m. | 19 minutes ago
Description :Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...