Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cal.com, Inc.

Cal.com, Inc. Vendor Cyber Rating & Cyber Score

cal.com

Open Source Scheduling Infrastructure


Cal.com, Inc. A.I CyberSecurity Scoring

Cal.com, Inc.
Company Information
Website:https://cal.com
Employees number:45
Number of followers:5,830
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:cal.com
Cal.com, Inc. Risk Score (AI oriented)
Between 700 and 749
logo
Cal.com, Inc.Technology, Information and Internet
Updated:
10/03/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cal.com, Inc. Global Score (TPRM)
xxxx
logo
Cal.com, Inc.Technology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Cal.com, Inc.
Cal.com, Inc.Moderate
Current Score
749Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
765Before Incident
Vulnerability
13 Jan 2026Cal.com, Inc.
Cal.com: Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack Any User Account

Critical Authentication Bypass Flaw in Cal.com Exposes User Accounts to Takeover

748After Incident
CRITICAL-17
CAL1768964190
Critical Authentication Bypass Flaw in Cal.com Exposes User Accounts to Takeover A severe vulnerability in Cal.com, an open-source scheduling and booking platform, was recently disclosed, allowing attackers to bypass authentication and hijack any user account including administrators without requiring passwords, session tokens, or multi-factor authentication (MFA). Tracked as GHSA-7hg4-x4pr-3hrg, the flaw affects versions 3.1.6 through 6.0.6 and stems from a logic error in the platform’s custom NextAuth JWT callback. The vulnerability occurs when an attacker manipulates an API request to overwrite the email field in a JSON Web Token (JWT) without server-side validation. Since Cal.com’s backend reconstructs user sessions based on this unvalidated input, the forged token grants full authenticated access to the targeted account. Security mechanisms like 2FA or federated identity providers (IdPs) provide no protection, as the exploit bypasses trust checks entirely. Impact & Exploitation - Attackers can impersonate any user by knowing their email address. - Compromised accounts gain access to connected integrations (Google Calendar, Zoom), billing modules, and administrative permissions. - A single API request is sufficient to execute the attack, requiring minimal effort. Remediation & Response Cal.com released a patch in version 6.0.7, securing hosted instances immediately. Self-hosted deployments must upgrade to the latest version to mitigate risk. As of disclosure, no active exploitation has been detected in the wild, though security experts recommend rotating exposed API tokens as a precaution. The flaw underscores the critical need for strict input validation in JWT-based authentication systems, particularly when handling client-controlled data.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Data Compromised: User account access, connected integrations (Google Calendar, Zoom), billing modules, administrative permissionsSystems Affected: Cal.com (versions 3.1.6 through 6.0.6)Operational Impact: Account takeover, unauthorized access to integrations and administrative functionsBrand Reputation Impact: Potential reputational damage due to authentication bypass vulnerabilityIdentity Theft Risk: High (account impersonation)
DATA BREACH
Type Of Data Compromised: User account credentials, session tokens, connected integration dataSensitivity Of Data: High (account access, administrative permissions)Personally Identifiable Information: Email addresses, user account details
DECEMBER 2025
765Before Incident
NOVEMBER 2025
765Before Incident
OCTOBER 2025
765Before Incident
SEPTEMBER 2025
765Before Incident
AUGUST 2025
765Before Incident
JULY 2025
765Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cal.com, Inc. ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in October 2025 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in September 2025 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in August 2025 ?
?
What was Cal.com, Inc.'s A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Cal.com, Inc.'s A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cal.com, Inc. ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cal.com, Inc.'s profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?