CVE-2025-66489

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-12-03 20:16

Updated : 2025-12-04 17:15


NVD link : CVE-2025-66489

Mitre link : CVE-2025-66489

CVE.ORG link : CVE-2025-66489


JSON object : View

Products Affected

No product.

CWE
CWE-303

Incorrect Implementation of Authentication Algorithm