CVE-2026-45286
בינונית 4.3
תיאור (מקור, אנגלית)
Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-7/8/2026
- CWE
- CWE-200
מוצרים מושפעים
nextcloud: calendar
קישורים
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r697… MitigationVendor Advisory
- https://github.com/nextcloud/calendar/issues/7971 ExploitIssue TrackingPatch
- https://github.com/nextcloud/calendar/pull/8197 Issue TrackingPatch
- https://hackerone.com/reports/3540663 Permissions Required