← Back to browse · API

CVE-2025-66489

Severity
CRITICAL
CVSS
9.9
EPSS
0.00852
Risk score
39.9
CISA KEV
No
PoC
No
Published
2025-12-03
Modified
2025-12-03
First seen
2026-08-07
Aliases
EUVD-2025-201128
Products
calcom:cal.com < 5.9.8
Sources
euvd EUVD-2025-201128

Description

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.

References