Vulnerabilities
Vulnerable Software
Cal:  >> Cal.com  >> 3.2.1  Security Vulnerabilities
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.
CVSS Score
10.0
EPSS Score
0.001
Published
2026-01-13
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
CVSS Score
9.9
EPSS Score
0.002
Published
2025-12-03


Contact Us

Shodan ® - All rights reserved