CVE-2026-104054

Source
https://cve.org/CVERecord?id=CVE-2026-104054
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104054.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104054
Published
2026-10-02T02:00:11Z
Modified
2026-10-04T02:30:44Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
Details

A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-862",
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104054.json"
}
References

Affected packages

Git / github.com/calcom/cal.diy

Affected ranges

Type
GIT
Repo
https://github.com/calcom/cal.diy
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "6.0"
        },
        {
            "last_affected":  "6.0"
        },
        {
            "introduced":  "6.1"
        },
        {
            "last_affected":  "6.1"
        },
        {
            "introduced":  "6.2.0"
        },
        {
            "last_affected":  "6.2.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

6.*
6.0
6.1
6.2.0
v6.*
v6.0.0
v6.0.1
v6.0.10
v6.0.11
v6.0.12
v6.0.13
v6.0.2
v6.0.3
v6.0.4
v6.0.5
v6.0.6
v6.0.7
v6.0.8
v6.0.9
v6.1.0
v6.1.1
v6.1.10
v6.1.11
v6.1.12
v6.1.13
v6.1.14
v6.1.15
v6.1.16
v6.1.2
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.1.7
v6.1.8
v6.1.9
v6.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104054.json"