10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
Description
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.
AI Analysis
Authentication bypass vulnerability via unvalidated email in custom JWT callback
Basic Information
ID
CVE-2026-23478
Source
GitHub_M
Published
Jan 13, 2026 at 21:37
Affected Product
Vendor
calcom
Product
cal.com
Version
>= 3.1.6, < 6.0.7
Affected Versions
calcom cal.com >= 3.1.6, < 6.0.7
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Cal.com
Product
cal.com
Version
3.1.6 to 6.0.7