CVE-2026-23478: Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23478?
CVE-2026-23478 is classified as a critical vulnerability due to potential unauthorized access to user accounts.
How do I fix CVE-2026-23478?
To fix CVE-2026-23478, upgrade Cal.com to version 6.0.7 or later.
Who is affected by CVE-2026-23478?
CVE-2026-23478 affects users of Cal.com versions from 3.1.6 through 6.0.6.
What is the impact of CVE-2026-23478?
The impact of CVE-2026-23478 allows attackers to gain full access to any user's account through authentication bypass.
What should I do if I cannot upgrade to fix CVE-2026-23478?
If unable to upgrade, implement additional security measures such as restricting access to the application or monitoring for unauthorized activity.