AI description
CVE-2025-66489 is an authentication bypass vulnerability affecting Cal.com, an open-source scheduling software. The vulnerability exists in versions prior to 5.9.8. It stems from a flaw in the login credentials provider that allows attackers to bypass password verification when a Time-based One-Time Password (TOTP) code is provided. This is due to problematic conditional logic in the authentication flow within the authorize() function. The vulnerability can be exploited in two scenarios. In the first, attackers can bypass both password and TOTP verification by submitting any non-empty value in the totpCode field along with the victim's email address. In the second scenario, users with 2FA enabled are also affected, as the system ignores the password even when validating the TOTP code. Cal.com version 5.9.8 addresses this vulnerability.
- Description
- Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-303
- Hype score
- Not currently trending
A critical flaw (CVE-2025-66489) in Cal. com allowed attackers to bypass authentication by submitting any non-empty TOTP field. Versions up to 5.9.7 were affected. Upgrade to 5.9.8 to restore proper password + TOTP validation. How should platforms better validate MFA logic? htt
@TechNadu
9 Dec 2025
77 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Alert🚨:CVE-2025-66489(CVSS 9.9): Critical https://t.co/35GmBAkM6D Flaw Allows Authentication Bypass by Submitting Fake TOTP Codes 🧐Detail:https://t.co/tlIDEzLsKh 📊15.2K Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/GePbgtG7RM
@HunterMapping
9 Dec 2025
4340 Impressions
10 Retweets
64 Likes
24 Bookmarks
2 Replies
0 Quotes
🚨🚨CVE-2025-66489 (CVSS 9.9): https://t.co/Bc24fzUHWX Authentication Bypass If an attacker supplies any TOTP code during login, the password check is completely skipped thanks to broken conditional logic. Search by vul.cve Filter👉vul.cve="CVE-2025-66489" ZoomEye https://
@zoomeye_team
8 Dec 2025
11528 Impressions
10 Retweets
88 Likes
60 Bookmarks
0 Replies
2 Quotes