CVE-2026-23478Disclosure(cal / cal.com)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cal cal.com systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-602CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cal.com

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cal.com

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-20: 1Mentions · 2026-05-01: 1Mentions · 2026-05-24: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-02-20: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-24: 102-2005-0105-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-201
Disclosure1
2026-05-011
Disclosure1
2026-05-241
Patch1
Full discourse3 posts
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-23478: a CVSS 10.0 auth bypass in @calcom. The JWT callback trusts a user-supplied email from session.update() - pass any address, take that account. What matters for agent builders: a prompt-injected agent hitting the http://Cal.com API becomes admin with no password, no 2FA. Patch to 6.0.7 and kill every active session. https://www.sentinelone.com/vulnerability-database/cve-2026-23478/

    Post summary

    The post details a critical auth bypass in Cal.com’s JWT callback, highlights a CVSS 10.0 score, and provides the remedy—updating to patch 6.0.7 and terminating all active sessions.

    00100160
    398 followersView on X
  • InnoScout@innoscoutpro
    Disclosure

    http://Cal.com just closed its core codebase and named the reason explicitly. Five years as open source champions. Then CVE-2026-23478 hit: critical auth bypass, http://Cal.com versions 3.1.6 to less than 6.0.7. AI tools found it in weeks not months. The founder's conclusion: in a world where AI scans, maps and exploits at near zero cost, transparency becomes exposure. http://Cal.diy stays MIT-licensed for hobbyists. The main product goes proprietary. The CVE is confirmed real by NVD and GitHub Security Advisories. Hex Security quantified the shift: open source is 5 to 10 times easier to exploit in the AI era. Anthropic's Mythos model found a serious hole in OpenBSD, one of the world's most security-conscious projects, in autonomous testing. The old logic: transparency equals more finders equals more fixes equals safe. New logic: AI removes the cost barrier on both sides, but attackers move faster than defenders can patch. This is not just http://Cal.com's problem. Any open source project handling sensitive data faces the same calculus. The two-tier model, community fork plus closed core, may become the industry template.

    Post summary

    CVE-2026-23478 is confirmed as a critical authentication bypass in Cal.com affecting versions 3.1.6 to less than 6.0.7; the post underscores the vulnerability details and broader implications of AI-driven discovery, but does not cite active exploitation or a patch.

    0000033
    30 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #AccountTakeover One API Call to Hijack: Critical http://Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA https://securityonline.info/one-api-call-to-hijack-critical-cal-com-flaw-cve-2026-23478-cvss-10-bypasses-2fa/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a critical CVE‑2026‑23478 flaw in Cal.com that allows bypassing two‑factor authentication with a single API call, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000019
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcalcal.com---

Explore more