Skip to content
ThreatCluster

Cal.com Vulnerability Allows Bypass of Authentication with Fake TOTP Codes

First seen 8 Dec 2025, 14:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical vulnerability in Cal.com has been identified that enables attackers to bypass authentication by using fake Time-based One-Time Password (TOTP) codes. This flaw poses a significant risk to users relying on TOTP for secure access. The specific details regarding the discovery and exploitation of this vulnerability have been reported by multiple cybersecurity news platforms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track Cal.com in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed