Cal.com Vulnerability Allows Account Hijacking via Authentication Bypass

Cal.com Vulnerability Allows Account Hijacking via Authentication Bypass

First seen 15 Jan 2026, 14:53 UTC CybersecuritynewsGbhackers 57.3

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Cal.com's scheduling platform allows attackers to bypass authentication and hijack user accounts. Tracked as CVE-2026-23478, this flaw affects versions from 3.1.6 to below 6.0.7, with patches available in version 6.0.7 and later. The issue is linked to a weakness in the NextAuth JWT callback mechanism.