Beveiligingsadvies

CVE-2026-23478

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-13 21:37:35
Laatst bijgewerkt 2026-01-14 16:56:25
Toegewezen door GitHub_M
CVSS-score 10.0
Status PUBLISHED

Beschrijving

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.