logo

One API Call to Hijack: Critical Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA

ID: deb5f1de-a1ec-569d-8ba9-1642340dea6e

STIX ID: report--deb5f1de-a1ec-569d-8ba9-1642340dea6e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** A critical CVE-2026-23478 in Cal.com (CVSS 10.0) allows remote attackers to bypass authentication and fully hijack user accounts by issuing a session.update with a target email, enabling immediate access to bookings, billing, organization membership, and bypassing 2FA or external IdP protections; affected self-hosted versions are 3.1.6 through 6.0.6 and Cal.com released 6.0.7 to remediate, with hosted deployments patched and no reported exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.