Skip to content
Cal.com Vulnerability Allows Account Hijacking via Authentication Bypass

Cal.com Vulnerability Allows Account Hijacking via Authentication Bypass

First seen 15 Jan 2026, 14:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical vulnerability in Cal.com's scheduling platform allows attackers to bypass authentication and hijack user accounts. Tracked as CVE-2026-23478, this flaw affects versions from 3.1.6 to below 6.0.7, with patches available in version 6.0.7 and later. The issue is linked to a weakness in the NextAuth JWT callback mechanism.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2026-23478 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed