CVE Database
/

CVE-2026-23478

Back to search

CVE-2026-23478

Published: Jan 13, 2026

Modified: Jan 14, 2026

PUBLISHED

Description

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.

VendorProductVersions

calcom

cal.com

affected
>= 3.1.6, < 6.0.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-23478 - Security Vulnerability | QwikSec