Sceawere
Vulnerability Detail
CVE-2026-104054UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cal.com Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 21h ago
- Vendor
- calcom
- Product
- cal.diy
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-02T02:17:01.740Z",
"pubdate": "2026-10-02T02:17:01.740Z",
"executiveSummary": "A critical authorization flaw has been identified in the PBAC (Policy-Based Access Control) Permission Engine within calcom cal.diy up to version 6.2.0. The vulnerability resides in the doesUserIdHaveAccessToBooking function of the BookingAccessService.ts file, leading to a missing authorization condition.\nThis vulnerability allows remote, unauthenticated or unauthorized attackers to bypass intended security constraints. By manipulating request parameters or exploiting the logic error within the access control function, an attacker can gain unauthorized access to booking data they are not permitted to view or manage.\nThe risk is severe as the vulnerability has been publicly disclosed with functional exploit code already available in the wild, increasing the likelihood of active exploitation. Organizations utilizing affected versions are at immediate risk of data exposure and potential unauthorized administrative actions related to bookings.\nExploitation does not require prior authentication in the context of the affected engine's logic, enabling remote adversaries to leverage this missing check to compromise the confidentiality and integrity of the scheduling system.",
"technicalDetails": "The vulnerability is localized within the PBAC Permission Engine, specifically inside the BookingAccessService.ts file. The root cause is a flaw in the doesUserIdHaveAccessToBooking function, which fails to correctly validate the user's relationship or authorization level against the requested booking ID during the permission evaluation process.\nIn the affected versions (up to 6.2.0), the application relies on this function to determine if a specific user context has the necessary permissions to perform operations on a booking entity. Due to improper implementation or logic gaps within this check, the system fails to enforce strict access control boundaries. When a request is processed, the function returns an incorrect positive or fails to abort the execution flow, effectively granting authorization to entities that should have been restricted.\nThe attack flow commences with a remote attacker identifying a target booking ID. By invoking endpoints or API methods that utilize the BookingAccessService.ts engine, the attacker initiates a request containing a malicious payload designed to interact with the booking. The PBAC engine triggers the doesUserIdHaveAccessToBooking function to verify if the requester has legitimate access. Because the logic is flawed, the function fails to validate the ownership or administrative rights of the requester, allowing the request to proceed as authorized.\nThis exploit is particularly dangerous because it bypasses the security layer intended to protect sensitive user data. Since the exploit is publicly available, the barrier to entry for an attacker is minimal. The impact involves unauthorized data exfiltration, where an attacker can access sensitive scheduling information, including participant details, meeting times, and potentially internal booking metadata. Furthermore, depending on the implementation of the downstream controllers, this missing authorization could allow for unauthorized modifications, deletions, or data corruption within the booking database.\nThe vulnerability highlights a breakdown in secure access control enforcement where the implementation of Policy-Based Access Control logic fails to account for boundary conditions in user-to-booking mapping. Without an effective patch, the system continues to exhibit inconsistent authorization behavior, leaving the booking layer exposed to remote manipulation without necessitating valid session tokens or existing high-level privilege access."
}