CVE-2025-66489: Cal.com Authentication Bypass via bad TOTP + password checks
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66489?
CVE-2025-66489 is considered a high-severity vulnerability due to the potential for unauthorized access to user accounts.
How do I fix CVE-2025-66489?
To fix CVE-2025-66489, upgrade to Cal.com version 5.9.8 or later where this vulnerability is addressed.
What impact does CVE-2025-66489 have on user accounts?
CVE-2025-66489 allows attackers to bypass password verification, potentially compromising the security of user accounts.
Is CVE-2025-66489 present in versions after 5.9.8?
No, CVE-2025-66489 is only present in versions prior to 5.9.8 of Cal.com.
Who is affected by CVE-2025-66489?
Users of Cal.com versions prior to 5.9.8 are affected by CVE-2025-66489.