logo

Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack Any User Account

ID: ef9da0cb-8d3a-5129-88be-570ba3fed517

STIX ID: report--ef9da0cb-8d3a-5129-88be-570ba3fed517

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Varshini

...
...

Cal.com versions 3.1.6 through 6.0.6 contain a critical authentication bypass (GHSA-7hg4-x4pr-3hrg) caused by a NextAuth JWT callback that trusts client-supplied input when handling the "update" event, allowing attackers to forge JWTs (via session.update({ email: ... })) and impersonate any user including admins; the issue was fixed in 6.0.7, hosted deployments were patched immediately, and self-hosted users are urged to upgrade and rotate exposed tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.