Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Cal.com Flaw Allows Attackers to Bypass Authentication Using Fake TOTP Codes

Cal.com has identified a critical authentication bypass vulnerability (CVE-2025-66489) that enables unauthorized access to user accounts by exploiting a flaw in password verification logic.

Cal.com has identified a critical authentication bypass vulnerability (CVE-2025-66489) that enables unauthorized access to user accounts by exploiting a flaw in password verification logic.

This vulnerability, assigned a CVSS v4 score of 9.3, affects all Cal.com versions up to and including 5.9.7. Users are advised to update to version 5.9.8 immediately to mitigate potential risks.

The issue resides in the credentials provider's authentication logic within the authorize() function, specifically in packages/features/auth/lib/next-auth-options.ts. The flaw involves a conditional logic error that bypasses password verification when a TOTP (Time-based One-Time Password) code is submitted, regardless of its validity.

Attackers can bypass both password and TOTP verification by entering any non-empty value in the totpCode field with the victim’s email address. Users without 2FA are particularly vulnerable. For users with 2FA, the system bypasses password verification when a TOTP code is provided, reducing multi-factor authentication to single-factor, thereby weakening security.

This vulnerability, assigned a CVSS v4 score of 9.3, affects all Cal.com versions up to and including 5.9.7.
Laura Mitchell · Thehackingpost

The vulnerable code appears at lines 179-187 of the authentication file, where the presence of a totpCode in a request causes the password verification step to be skipped entirely.

This flaw poses significant risks, potentially exposing sensitive user information, enabling user enumeration, account impersonation, and unauthorized access to privileged accounts. The vulnerability has been classified under CWE-303 (Incorrect Implementation of Authentication Algorithm).

Cal.com has released version 5.9.8 to address this critical security flaw. Organizations and individual users are strongly urged to upgrade to the patched release to safeguard against potential exploitation.

Advertisement

The update ensures proper verification of both password and TOTP codes, restoring the intended security of multi-factor authentication.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories