CVE-2026-23478
EUVD-2026-241313.01.2026, 22:16
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cal | cal.com | 3.1.6 ≤ 𝑥 < 6.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration