216.73.217.22

CVE-2026-23478

· Published 13/01/2026 22:16 · Modified 14/01/2026 16:25

Labels: CVE-2026-23478 2026-01-13CVE-2026-23478CWE-602[email protected]

Essential information

Published
13/01/2026 22:16
Modified
14/01/2026 16:25
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cal / cal cpe:2.3:a:cal:cal:3.1.6-6.0.6:*:*:*:*:*:*:*

References