Recently, a severe vulnerability, identified as CVE-2026-9349, was found in calcom's cal.diy software, up to version 4.9.4. This flaw involves the getServerSideProps function within the web module for bookings and could lead to significant security breaches.
According to the reports, this issue leads to information disclosure when the arguments cancelledBy or rescheduledBy are manipulated. The attack can be executed remotely, putting many Linux servers at risk of exploitation.
For system administrators and hosting providers, vulnerabilities like CVE-2026-9349 are a critical concern. Such flaws not only threaten the integrity of web applications but can also lead to security incidents that compromise sensitive data.
Ignoring vulnerabilities exposes your infrastructure to malware detection issues and brute-force attacks. Thus, it’s essential to stay ahead of potential threats by promptly addressing these security alerts.
To protect your servers from this vulnerability, here are some practical steps:
Strengthen your server security today! Start your journey toward proactive protection by trying BitNinja’s free 7-day trial. Explore how our platform can help you safeguard your infrastructure against emerging threats.




