Critical Cal.com Vulnerability Let Attackers Bypass Authentication Via Fake TOTP Codes
ID: 6759a125-9307-5fcf-bcc4-dcef815f070a
STIX ID: report--6759a125-9307-5fcf-bcc4-dcef815f070a
Feed Name: cybersecurityNews.com
Threat Score
A critical authentication bypass (CVE-2025-66489) in cal.com versions up to 5.9.7 allows attackers to bypass password and TOTP verification by providing any non-empty TOTP value; the issue is caused by flawed conditional logic in the authorize() function and has been patched in version 5.9.8 — users should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
