SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63768

MEDIUM · CVSS 4.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

An open redirect vulnerability exists in the conferencing OAuth callback endpoint of cal.diy versions up to 6.2.0, allowing attackers to exploit the unsigned state parameter and onErrorReturnTo field. This can lead to users being redirected to malicious URLs, facilitating phishing attacks. Organizations using affected versions should prioritize patching this vulnerability to protect their users from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63768
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.