Categories: Cyber Security News

Cal.com Broken Access Controls Exposes Millions of Bookings and Leads to Complete Account Takeover

Cal.com, an open-source scheduling platform that millions of people use to book meetings and manage their calendars, recently faced a serious security problem.

The platform provides an alternative to tools like Calendly, offering features like calendar syncing, team scheduling, and video conferencing.

On January 26, 2026, security researchers discovered that attackers could break into any user’s account and access sensitive booking information belonging to entire organizations.

The vulnerability discovered in Cal.com Cloud involved a chain of three separate but connected security flaws that worked together to create a complete account takeover.

These weaknesses existed in the platform’s signup process and booking data endpoints. When combined, they allowed attackers to hijack user accounts and steal private meeting details, attendee names, emails, and complete booking histories from millions of bookings stored on the platform.

Gecko Security analysts identified these critical security issues through an AI-powered security analysis tool that scanned the Cal.com codebase.

The researchers found that the platform’s defenses had multiple gaps that could be exploited sequentially.

Their investigation revealed how subtle bugs in core components could chain together and completely dismantle the platform’s security boundaries, affecting admin accounts and paid users alike.

How the Authentication Bypass Worked

The most dangerous flaw was an authentication bypass that allowed attackers to take over existing user accounts through organization invite tokens.

The vulnerability started with a flawed username validation function that failed to check properly whether an email address was already registered.

When someone tried to sign up using an organization invite link, the system incorrectly approved signups for users who already had accounts with the platform.

The attack happened in three steps. First, the signup validation incorrectly allowed users already in organizations to bypass security checks. Second, email validation only searched within the attacker’s organization, missing victims in other organizations.

Finally, the database operation used globally unique email addresses to match users, which meant it overwrote the victim’s password with the attacker’s chosen password.

To exploit this, an attacker simply generated a shareable invite link, navigated to the signup page, entered any victim’s email address and their chosen password, and gained full account access.

No warning was sent to the actual account owner. Cal.com patched this issue in version 6.0.8 by adding proper user existence checks before signup.

The second vulnerability exposed booking data through Insecure Direct Object References on API endpoints, allowing any authenticated user to read and delete all bookings platform-wide. Cal.com blocked direct access to these internal route handlers and released fixes within days of the report.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

The post Cal.com Broken Access Controls Exposes Millions of Bookings and Leads to Complete Account Takeover appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Community action garden grants available for neighborhood groups in Rockford

ROCKFORD, Ill. (WTVO) — The Community Action Garden grants are now available for all neighborhood,…

46 minutes ago

Illinois Senate battle set: Stratton vs. Tracy in 2026 showdown

Illinois Lt. Gov. Juliana Stratton, backed by Gov. J.B. Pritzker, will face Republican Don Tracy…

47 minutes ago

US Senate Republicans launch debate on SAVE Act requiring photo ID to vote

The U.S. Capitol on March 3, 2026. (Photo by Jennifer Shutt/States Newsroom)WASHINGTON — U.S. Senate…

1 hour ago

Belvidere School Board releases survey findings on Facility Master Plans

The Belvidere School Board has released survey regarding their Masters Facility Plans. A big question…

2 hours ago

Darren Bailey secures Republican nomination, sets sights on Gov. Pritzker rematch

Darren Bailey has won the Republican nomination for Illinois Governor, promising to cut taxes, reduce…

2 hours ago

Grab Frank Herbert’s Dune Box Set at a Major Discount Before the Dune: Part 3 Hype Increases the Price

The new trailer for Dune: Part 3 just dropped and it looks incredible. The third…

4 hours ago

This website uses cookies.