Signal is active with 1 mentions in latest observed window
Immediate actions
Patch cal cal.com systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.
CVE-2026-23478: a CVSS 10.0 auth bypass in @calcom. The JWT callback trusts a user-supplied email from session.update() - pass any address, take that account. What matters for agent builders: a prompt-injected agent hitting the http://Cal.com API becomes admin with no password, no 2FA. Patch to 6.0.7 and kill every active session.
https://www.sentinelone.com/vulnerability-database/cve-2026-23478/
Post summary
The post details a critical auth bypass in Cal.com’s JWT callback, highlights a CVSS 10.0 score, and provides the remedy—updating to patch 6.0.7 and terminating all active sessions.
http://Cal.com just closed its core codebase and named the reason explicitly. Five years as open source champions. Then CVE-2026-23478 hit: critical auth bypass, http://Cal.com versions 3.1.6 to less than 6.0.7. AI tools found it in weeks not months.
The founder's conclusion: in a world where AI scans, maps and exploits at near zero cost, transparency becomes exposure. http://Cal.diy stays MIT-licensed for hobbyists. The main product goes proprietary.
The CVE is confirmed real by NVD and GitHub Security Advisories. Hex Security quantified the shift: open source is 5 to 10 times easier to exploit in the AI era. Anthropic's Mythos model found a serious hole in OpenBSD, one of the world's most security-conscious projects, in autonomous testing.
The old logic: transparency equals more finders equals more fixes equals safe. New logic: AI removes the cost barrier on both sides, but attackers move faster than defenders can patch.
This is not just http://Cal.com's problem. Any open source project handling sensitive data faces the same calculus. The two-tier model, community fork plus closed core, may become the industry template.
Post summary
CVE-2026-23478 is confirmed as a critical authentication bypass in Cal.com affecting versions 3.1.6 to less than 6.0.7; the post underscores the vulnerability details and broader implications of AI-driven discovery, but does not cite active exploitation or a patch.
#VulnerabilityReport#AccountTakeover One API Call to Hijack: Critical http://Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA https://securityonline.info/one-api-call-to-hijack-critical-cal-com-flaw-cve-2026-23478-cvss-10-bypasses-2fa/?utm_source=dlvr.it&utm_medium=twitter
Post summary
The tweet announces a critical CVE‑2026‑23478 flaw in Cal.com that allows bypassing two‑factor authentication with a single API call, but does not provide a PoC, exploit, patch, or evidence of active exploitation.