Cal.com, Inc. A.I CyberSecurity Scoring
Cal.com, Inc.
Company Information
Website:https://cal.com
Employees number:45
Number of followers:5,830
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:cal.com
Cal.com, Inc. Risk Score (AI oriented)
Between 700 and 749
Cal.com, Inc.Technology, Information and Internet
Updated:
10/03/2026
10/03/2026
749/1000
Moderate
Ba
Cal.com, Inc. Global Score (TPRM)
xxxx
Cal.com, Inc.Technology, Information and Internet
Score locked

Cal.com, Inc.Moderate
Current Score
749Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749
MAY 2026
749
APRIL 2026
749
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
765
Vulnerability
13 Jan 2026 • Cal.com, Inc.
Cal.com: Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack Any User Account
Critical Authentication Bypass Flaw in Cal.com Exposes User Accounts to Takeover
748
CRITICAL-17
CAL1768964190
Critical Authentication Bypass Flaw in Cal.com Exposes User Accounts to Takeover
A severe vulnerability in Cal.com, an open-source scheduling and booking platform, was recently disclosed, allowing attackers to bypass authentication and hijack any user account including administrators without requiring passwords, session tokens, or multi-factor authentication (MFA). Tracked as GHSA-7hg4-x4pr-3hrg, the flaw affects versions 3.1.6 through 6.0.6 and stems from a logic error in the platform’s custom NextAuth JWT callback.
The vulnerability occurs when an attacker manipulates an API request to overwrite the email field in a JSON Web Token (JWT) without server-side validation. Since Cal.com’s backend reconstructs user sessions based on this unvalidated input, the forged token grants full authenticated access to the targeted account. Security mechanisms like 2FA or federated identity providers (IdPs) provide no protection, as the exploit bypasses trust checks entirely.
Impact & Exploitation
- Attackers can impersonate any user by knowing their email address.
- Compromised accounts gain access to connected integrations (Google Calendar, Zoom), billing modules, and administrative permissions.
- A single API request is sufficient to execute the attack, requiring minimal effort.
Remediation & Response
Cal.com released a patch in version 6.0.7, securing hosted instances immediately. Self-hosted deployments must upgrade to the latest version to mitigate risk. As of disclosure, no active exploitation has been detected in the wild, though security experts recommend rotating exposed API tokens as a precaution.
The flaw underscores the critical need for strict input validation in JWT-based authentication systems, particularly when handling client-controlled data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
765
NOVEMBER 2025
765
OCTOBER 2025
765
SEPTEMBER 2025
765
AUGUST 2025
765
JULY 2025
765
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Cal.com, Inc. ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in May 2026 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in April 2026 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in March 2026 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in February 2026 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in January 2026 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in December 2025 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in November 2025 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in October 2025 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in September 2025 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in August 2025 ??
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Cal.com, Inc.'s A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Cal.com, Inc. ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Cal.com, Inc.'s profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?