One API Call to Hijack: Critical Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA
ID: deb5f1de-a1ec-569d-8ba9-1642340dea6e
STIX ID: report--deb5f1de-a1ec-569d-8ba9-1642340dea6e
Feed Name: securityonline.info
**Executive summary:** A critical CVE-2026-23478 in Cal.com (CVSS 10.0) allows remote attackers to bypass authentication and fully hijack user accounts by issuing a session.update with a target email, enabling immediate access to bookings, billing, organization membership, and bypassing 2FA or external IdP protections; affected self-hosted versions are 3.1.6 through 6.0.6 and Cal.com released 6.0.7 to remediate, with hosted deployments patched and no reported exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
