Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack any User Account

A significant vulnerability has been identified in Cal.com's scheduling platform, affecting authentication processes. This flaw, tracked as CVE-2026-23478, permits attackers to hijack user accounts by exploiting a weakness in the NextAuth JWT callback…

A significant vulnerability has been identified in Cal.com's scheduling platform, affecting authentication processes. This flaw, tracked as CVE-2026-23478, permits attackers to hijack user accounts by exploiting a weakness in the NextAuth JWT callback mechanism.

The vulnerability impacts Cal.com versions from 3.1.6 up to, but not including, 6.0.7. Patches have been released starting with version 6.0.7. The issue arises from a custom NextAuth JWT callback that inadequately manages client-controlled identity inputs during session updates.

CVE ID: CVE-2026-23478 Affected Versions: >= 3.1.6 < 6.0.7 CVSS v4 Score: Critical / 10 Attack Vector: Network CWE-602: Client-Side Enforcement of Server-Side Security CWE-639: Authorization Bypass Through User-Controlled Key

The vulnerability allows an attacker to execute an API call using the session.update({email: "victim@example.com"}), altering the JSON Web Token (JWT) to incorporate the attacker's subject identifier along with the victim's email. Subsequent requests with this modified JWT authenticate as the victim, as the application utilizes the token email field controlled by the attacker to query the user database.

A significant vulnerability has been identified in Cal.com's scheduling platform, affecting authentication processes.
Charles Nolan · Thehackingpost

The exploitation of this flaw grants complete control over victim accounts, including access to bookings, event types, integrations, organization memberships, billing details, and administrative privileges. The attack can be executed at scale with minimal effort, requiring only the target's email address and a single API call. Cal.com has patched hosted deployments following the discovery.

Organizations using self-hosted instances of Cal.com are advised to upgrade to version 6.0.7 or later to mitigate this risk. The vulnerability was reported by a security researcher through Veri-Labs, with no indication of active exploitation in the wild. The flaw exemplifies the potential consequences of inadequate client-side control over server-side security mechanisms, even in otherwise secure platforms.

Advertisement

For further technical details, please refer to the official advisory .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories