Cal.com Broken Access Controls Lead to Account Takeover and Data Exposure
ID: 27aa1a56-0d2d-5353-a6a7-796b0bf09636
STIX ID: report--27aa1a56-0d2d-5353-a6a7-796b0bf09636
Feed Name: GBHackers
Gecko discovered and reported critical broken access control vulnerabilities in Cal.com: an authentication bypass in the organization signup flow that enabled account takeover using only an email and invite link, and misconfigured Next.js internal API routes that exposed and allowed deletion of booking and calendar data across organizations. Cal.com patched the issues (v6.0.8 and middleware updates) after disclosure; the flaws could expose PII, OAuth tokens, API keys, and allow silent lockout of users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
