logo

Cal.com Broken Access Controls Lead to Account Takeover and Data Exposure

ID: 27aa1a56-0d2d-5353-a6a7-796b0bf09636

STIX ID: report--27aa1a56-0d2d-5353-a6a7-796b0bf09636

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Gecko discovered and reported critical broken access control vulnerabilities in Cal.com: an authentication bypass in the organization signup flow that enabled account takeover using only an email and invite link, and misconfigured Next.js internal API routes that exposed and allowed deletion of booking and calendar data across organizations. Cal.com patched the issues (v6.0.8 and middleware updates) after disclosure; the flaws could expose PII, OAuth tokens, API keys, and allow silent lockout of users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.